389-ds-base-2.8.0-9.el9_8

エラータID: AXSA:2026-1635:06

リリース日: 
2026/08/24 Monday - 17:36
題名: 
389-ds-base-2.8.0-9.el9_8
影響のあるチャネル: 
MIRACLE LINUX 9 for x86_64
Severity: 
High
Description: 

389 Directory Server is an LDAP version 3 (LDAPv3) compliant server. The base packages include the Lightweight Directory Access Protocol (LDAP) server and command-line utilities for server administration.

Security Fix(es):

* 389-ds-base: 389-ds-base: pre-auth LDAP filter injection in CleanAllRUV status check (CVE-2026-11770)
* 389-ds-base: 389-ds-base: NULL pointer dereference in deref control plugin BER parser (CVE-2026-11788)
* 389-ds-base: 389-ds-base: pre-authentication stack buffer overflow in get_ruvelement_from_berval() via unbounded replica ID parsing (CVE-2026-15722)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-11770
A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated replication plugin privileges and returns a boolean match result, the attacker can extract sensitive server configuration metadata, including replication bind DNs and password storage scheme information.
CVE-2026-11788
A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing an unauthenticated remote attacker to crash the LDAP server when the system is under memory pressure.
CVE-2026-15722
A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without bounds checking. A remote unauthenticated attacker can crash the LDAP server by sending a crafted StartNSDS50ReplicationRequest extended operation containing a replica ID field with more than 16 digit characters. The overflow occurs during payload decoding, before any authorization check. Stack protectors limit impact to denial of service.

解決策: 

Update packages.

追加情報: 

N/A

ダウンロード: 

SRPMS
  1. 389-ds-base-2.8.0-9.el9_8.src.rpm
    MD5: 298d29511f7e130d79039eca275bee64
    SHA-256: 9579913fb559fd34e49fc38cf43c1e1be13ef489c12c0a9ae958857544f04a70
    Size: 48.01 MB

Asianux Server 9 for x86_64
  1. 389-ds-base-2.8.0-9.el9_8.x86_64.rpm
    MD5: e23a89e85536f9c468e10c3b7a901274
    SHA-256: 962b4ca8f9e1e45122a414d8fb5f5c4ea0891926b5b447a7a6a29bb634d8e9fb
    Size: 3.00 MB
  2. 389-ds-base-devel-2.8.0-9.el9_8.x86_64.rpm
    MD5: 4699c28e56ed26a17069295c08c01a42
    SHA-256: 2749312abbabe0799fe561ae6310fdee1b051ce78acb34ae688cd68cf4e9cbbf
    Size: 127.07 kB
  3. 389-ds-base-libs-2.8.0-9.el9_8.x86_64.rpm
    MD5: b0fa04cb1636226caefe77636bc700c9
    SHA-256: ac5620254a1cca5e031fdd6a2c13973af7d742102a093e54da89a0181689c0a4
    Size: 1.51 MB
  4. 389-ds-base-snmp-2.8.0-9.el9_8.x86_64.rpm
    MD5: bfd28697b58f3edb5012dc00322ced76
    SHA-256: df9c70a7ec432f451df90dd449018b8f39d3b59ab1413b6144e06d816f6169dc
    Size: 49.30 kB
  5. python3-lib389-2.8.0-9.el9_8.noarch.rpm
    MD5: 5b64bf96cfbe4af4ffd4cd7174116b77
    SHA-256: d54f99449668bf7c4dc8a80ddbbdc5bdb6a54fb550d9caf78a7d4c8f7cc9f071
    Size: 1.10 MB