389-ds-base-2.8.0-10.el9_8

エラータID: AXSA:2026-1821:07

Release date: 
Monday, September 14, 2026 - 18:49
Subject: 
389-ds-base-2.8.0-10.el9_8
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
High
Description: 

389 Directory Server is an LDAP version 3 (LDAPv3) compliant server. The base packages include the Lightweight Directory Access Protocol (LDAP) server and command-line utilities for server administration.

Security Fix(es):

* 389-ds-base: 389-ds-base: heap buffer overflow via SASL wrapped-record length lower-bound underflow in sasl_io_start_packet() (CVE-2026-18355)
* 389-ds-base: 389-ds-base: pre-authentication NULL pointer dereference via paged results and USE_ONE_BACKEND control in op_shared_search (CVE-2026-18453)
* 389-ds-base: 389-ds-base: SASL PLAIN authentication allows privilege escalation to Directory Manager via stale identity in Cyrus SASL auxiliary property (CVE-2026-18922)
* 389-ds-base: 389-ds: anonymous LDAP client can defeat SELFDN ACI bind-rule checks via empty bind DN (CVE-2026-76560)
* 389-ds-base: 389-ds-base: CVE-2026-11610 incomplete fix may introduce a connection-stall DoS (CVE-2026-78701)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-11610
A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). After a successful SASL bind with integrity protection (SSF > 0), an authenticated attacker can send a specially crafted oversized LDAP UNBIND packet that is copied into a 512-byte heap receive buffer without a bounds check in sasl_io_recv() in sasl_io.c. This allows up to approximately 2 megabytes of attacker-controlled data to overflow the buffer, causing a denial of service (server crash). In FreeIPA and Red Hat Identity Management deployments, any domain user with a valid Kerberos ticket, any enrolled host, or any service account can trigger this vulnerability over the network after authenticating via GSSAPI. The vulnerable code path has existed since approximately 2013 (389-ds-base 1.3.2) and was not addressed by the CVE-2025-14905 fix, which patched a separate heap overflow in schema.c only.
CVE-2026-18355
A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), the wrapped-record length read from the wire is validated only against an upper bound. A small wire length (0, 1, or 2) produces an encrypted_buffer_count below the already-consumed encrypted_buffer_offset, causing an unsigned subtraction underflow in sasl_io_read_packet(). PR_Recv is then requested to read approximately 4 GiB into a 1024-byte heap buffer, resulting in a heap buffer overflow with attacker-controlled content. After a successful SASL bind with integrity protection (SSF > 0), a remote authenticated attacker can cause a denial of service or potentially achieve remote code execution. This flaw is distinct from CVE-2026-11774, whose fix only guards against upper-bound overflow.
CVE-2026-18453
A flaw was found in 389 Directory Server. A missing NULL pointer check in the paged results handling of op_shared_search allows an unauthenticated remote attacker to crash the LDAP server by sending a crafted sequence of search requests using the USE_ONE_BACKEND control, resulting in denial of service.
CVE-2026-18922
A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent, unrelated successful bind, regardless of which SASL mechanism completes that second bind. An attacker can send a SASL PLAIN bind as cn=Directory Manager with an incorrect password, then complete a SASL ANONYMOUS bind on the same connection, causing the server to grant Directory Manager authority without any valid credentials. A variant using a valid low-privileged account's own successful bind instead of an anonymous one is also possible.
CVE-2026-76560
A flaw was found in 389 Directory Server. The SELFDN ACI bind-rule evaluator incorrectly matches an anonymous LDAP client's empty bind DN against an empty stored attribute value, allowing an unauthenticated client to satisfy access control checks intended to require a matching authenticated identity. This can allow an anonymous LDAP client to perform an operation, such as adding or modifying a directory entry, that a SELFDN-based ACI intended to restrict to a specific authenticated user.
CVE-2026-78701
A flaw was found in 389-ds-base. A remote, authenticated attacker could exploit a vulnerability in the Simple Authentication and Security Layer (SASL) UNBIND process. By sending a specially crafted request, the attacker can cause a connection to stall, leading to resource exhaustion and a Denial of Service (DoS) for the server.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. 389-ds-base-2.8.0-10.el9_8.src.rpm
    MD5: 1a67eab5eb14ea0e5e3c4b399951ccac
    SHA-256: 6b0cf27c1fda32690f7a3df1be59eac7da60b30e0314ddb6d7bd9d8acad0b12c
    Size: 48.05 MB

Asianux Server 9 for x86_64
  1. 389-ds-base-2.8.0-10.el9_8.x86_64.rpm
    MD5: 7a65a8aa8df7e941471d10a6a47b53d3
    SHA-256: f2ca7f5ce12c37b78de132cca3e448865ec68a90918832d2366c304019a4e8af
    Size: 2.99 MB
  2. 389-ds-base-devel-2.8.0-10.el9_8.x86_64.rpm
    MD5: df15ec1097b60f07aaf3a5f9e72730fa
    SHA-256: 37f0254f5e4e61dbaa0958619c0c268382ff39af0b13b7dba4ece6e55a100971
    Size: 127.46 kB
  3. 389-ds-base-libs-2.8.0-10.el9_8.x86_64.rpm
    MD5: 10a0f4954dea29ad7498fdf27469be93
    SHA-256: 0cd4ab53f02240a15d892eac1770c3873013dbc34878f69f068b97e0771f22a7
    Size: 1.51 MB
  4. 389-ds-base-snmp-2.8.0-10.el9_8.x86_64.rpm
    MD5: 40bc727efafab24b169ee2c43769bcb4
    SHA-256: 767b35998712cc0566593c380f11620c6fa6e6b9485f872cb6d5829a2108d4f1
    Size: 49.70 kB
  5. python3-lib389-2.8.0-10.el9_8.noarch.rpm
    MD5: 99d1800f3160d9ae580fcf9f86dd2b4f
    SHA-256: 52f2044fcba1e7a654bc93644e94f4163ffd04f491c2107115bcb38be91c5d30
    Size: 1.10 MB