: 389-ds-base-1.4.3.39-28.module+el8+2044+8274218c
エラータID: AXSA:2026-1839:01
389 Directory Server is an LDAP version 3 (LDAPv3) compliant server. The base packages include the Lightweight Directory Access Protocol (LDAP) server and command-line utilities for server administration.
Security Fix(es):
* 389-ds-base: 389-ds-base: heap buffer overflow via SASL wrapped-record length lower-bound underflow in sasl_io_start_packet() (CVE-2026-18355)
* 389-ds-base: 389-ds-base: pre-authentication NULL pointer dereference via paged results and USE_ONE_BACKEND control in op_shared_search (CVE-2026-18453)
* 389-ds-base: 389-ds-base: SASL PLAIN authentication allows privilege escalation to Directory Manager via stale identity in Cyrus SASL auxiliary property (CVE-2026-18922)
* 389-ds-base: 389-ds: anonymous LDAP client can defeat SELFDN ACI bind-rule checks via empty bind DN (CVE-2026-76560)
Bug Fix(es) and Enhancement(s):
* lib389: set nsDS5ReplicaBindDNGroup before ensure_agreement() [rhel-8.10.z] (JIRA:RHEL-244463)
* fix breaks replication total init when nsDS5ReplicaBindDNGroup is set after agreement creation [rhel-8.10.z] (JIRA:RHEL-248762)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-18355
A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), the wrapped-record length read from the wire is validated only against an upper bound. A small wire length (0, 1, or 2) produces an encrypted_buffer_count below the already-consumed encrypted_buffer_offset, causing an unsigned subtraction underflow in sasl_io_read_packet(). PR_Recv is then requested to read approximately 4 GiB into a 1024-byte heap buffer, resulting in a heap buffer overflow with attacker-controlled content. After a successful SASL bind with integrity protection (SSF > 0), a remote authenticated attacker can cause a denial of service or potentially achieve remote code execution. This flaw is distinct from CVE-2026-11774, whose fix only guards against upper-bound overflow.
CVE-2026-18453
A flaw was found in 389 Directory Server. A missing NULL pointer check in the paged results handling of op_shared_search allows an unauthenticated remote attacker to crash the LDAP server by sending a crafted sequence of search requests using the USE_ONE_BACKEND control, resulting in denial of service.
CVE-2026-18922
A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent, unrelated successful bind, regardless of which SASL mechanism completes that second bind. An attacker can send a SASL PLAIN bind as cn=Directory Manager with an incorrect password, then complete a SASL ANONYMOUS bind on the same connection, causing the server to grant Directory Manager authority without any valid credentials. A variant using a valid low-privileged account's own successful bind instead of an anonymous one is also possible.
CVE-2026-76560
A flaw was found in 389 Directory Server. The SELFDN ACI bind-rule evaluator incorrectly matches an anonymous LDAP client's empty bind DN against an empty stored attribute value, allowing an unauthenticated client to satisfy access control checks intended to require a matching authenticated identity. This can allow an anonymous LDAP client to perform an operation, such as adding or modifying a directory entry, that a SELFDN-based ACI intended to restrict to a specific authenticated user.
Modularity name:
Stream name:
Update packages.
A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), the wrapped-record length read from the wire is validated only against an upper bound. A small wire length (0, 1, or 2) produces an encrypted_buffer_count below the already-consumed encrypted_buffer_offset, causing an unsigned subtraction underflow in sasl_io_read_packet(). PR_Recv is then requested to read approximately 4 GiB into a 1024-byte heap buffer, resulting in a heap buffer overflow with attacker-controlled content. After a successful SASL bind with integrity protection (SSF > 0), a remote authenticated attacker can cause a denial of service or potentially achieve remote code execution. This flaw is distinct from CVE-2026-11774, whose fix only guards against upper-bound overflow.
A flaw was found in 389 Directory Server. A missing NULL pointer check in the paged results handling of op_shared_search allows an unauthenticated remote attacker to crash the LDAP server by sending a crafted sequence of search requests using the USE_ONE_BACKEND control, resulting in denial of service.
A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent, unrelated successful bind, regardless of which SASL mechanism completes that second bind. An attacker can send a SASL PLAIN bind as cn=Directory Manager with an incorrect password, then complete a SASL ANONYMOUS bind on the same connection, causing the server to grant Directory Manager authority without any valid credentials. A variant using a valid low-privileged account's own successful bind instead of an anonymous one is also possible.
A flaw was found in 389 Directory Server. The SELFDN ACI bind-rule evaluator incorrectly matches an anonymous LDAP client's empty bind DN against an empty stored attribute value, allowing an unauthenticated client to satisfy access control checks intended to require a matching authenticated identity. This can allow an anonymous LDAP client to perform an operation, such as adding or modifying a directory entry, that a SELFDN-based ACI intended to restrict to a specific authenticated user.
N/A
SRPMS
- 389-ds-base-1.4.3.39-28.module+el8+2044+8274218c.src.rpm
MD5: 903f7583dfc180c208ceb7a6b586c9c9
SHA-256: bae537faeb7fc83123528d24579df3a4c42c42990e85496a9c3aff437c9ebd7f
Size: 48.65 MB
Asianux Server 8 for x86_64
- 389-ds-base-1.4.3.39-28.module+el8+2044+8274218c.x86_64.rpm
MD5: d530a594f75e4873c1cc96e96347c9c7
SHA-256: 614a01fbb3129d01ce302165a681b05c4557cec63db5f9281f9cc1e9550da0e8
Size: 3.15 MB - 389-ds-base-debugsource-1.4.3.39-28.module+el8+2044+8274218c.x86_64.rpm
MD5: 162407f24957c9df9b17ac899ff0e670
SHA-256: a02b200a6a994ab4a990dcb6173df1d18b1c07de867dbe17f3b0808ee8307ce6
Size: 2.79 MB - 389-ds-base-devel-1.4.3.39-28.module+el8+2044+8274218c.x86_64.rpm
MD5: b3e8bfaa903dd234f5aa8c9036320f62
SHA-256: 4932b397eac8767ae0c10f6fc92c1898721cc0e1934fb42c75d0d122ab63a58a
Size: 137.35 kB - 389-ds-base-legacy-tools-1.4.3.39-28.module+el8+2044+8274218c.x86_64.rpm
MD5: cc67f27dae638370951581571df74522
SHA-256: 8615c6c94ef46a2ea35033d80a3b1fed78956f81662a63eb8311183ba1db29a3
Size: 288.83 kB - 389-ds-base-libs-1.4.3.39-28.module+el8+2044+8274218c.x86_64.rpm
MD5: 0e737626b51f439098f438f983aaa24a
SHA-256: dd19bd34ea4e5c1f97c8e2fc1ee477f32f90780b67610a5c53671eca3e749a8c
Size: 1.53 MB - 389-ds-base-snmp-1.4.3.39-28.module+el8+2044+8274218c.x86_64.rpm
MD5: 69d3b40b9d184873d89cbc1b0a983ec2
SHA-256: 5cad28f0f99c372f29297c570f2207461183cbd013a589d1e2c4a9f6a8a9fee5
Size: 50.45 kB - python3-lib389-1.4.3.39-28.module+el8+2044+8274218c.noarch.rpm
MD5: d543177dfd7eba17e2afcefaf978c4e8
SHA-256: c02f1d0c057f8083e2c38951da7b1bf7718beae3e71985c85659730ed3afb511
Size: 0.98 MB