389-ds-base-2.8.0-9.el9_8
エラータID: AXSA:2026-1635:06
389 Directory Server is an LDAP version 3 (LDAPv3) compliant server. The base packages include the Lightweight Directory Access Protocol (LDAP) server and command-line utilities for server administration.
Security Fix(es):
* 389-ds-base: 389-ds-base: pre-auth LDAP filter injection in CleanAllRUV status check (CVE-2026-11770)
* 389-ds-base: 389-ds-base: NULL pointer dereference in deref control plugin BER parser (CVE-2026-11788)
* 389-ds-base: 389-ds-base: pre-authentication stack buffer overflow in get_ruvelement_from_berval() via unbounded replica ID parsing (CVE-2026-15722)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-11770
A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated replication plugin privileges and returns a boolean match result, the attacker can extract sensitive server configuration metadata, including replication bind DNs and password storage scheme information.
CVE-2026-11788
A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing an unauthenticated remote attacker to crash the LDAP server when the system is under memory pressure.
CVE-2026-15722
A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without bounds checking. A remote unauthenticated attacker can crash the LDAP server by sending a crafted StartNSDS50ReplicationRequest extended operation containing a replica ID field with more than 16 digit characters. The overflow occurs during payload decoding, before any authorization check. Stack protectors limit impact to denial of service.
Update packages.
A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated replication plugin privileges and returns a boolean match result, the attacker can extract sensitive server configuration metadata, including replication bind DNs and password storage scheme information.
A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing an unauthenticated remote attacker to crash the LDAP server when the system is under memory pressure.
A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without bounds checking. A remote unauthenticated attacker can crash the LDAP server by sending a crafted StartNSDS50ReplicationRequest extended operation containing a replica ID field with more than 16 digit characters. The overflow occurs during payload decoding, before any authorization check. Stack protectors limit impact to denial of service.
N/A
SRPMS
- 389-ds-base-2.8.0-9.el9_8.src.rpm
MD5: 298d29511f7e130d79039eca275bee64
SHA-256: 9579913fb559fd34e49fc38cf43c1e1be13ef489c12c0a9ae958857544f04a70
Size: 48.01 MB
Asianux Server 9 for x86_64
- 389-ds-base-2.8.0-9.el9_8.x86_64.rpm
MD5: e23a89e85536f9c468e10c3b7a901274
SHA-256: 962b4ca8f9e1e45122a414d8fb5f5c4ea0891926b5b447a7a6a29bb634d8e9fb
Size: 3.00 MB - 389-ds-base-devel-2.8.0-9.el9_8.x86_64.rpm
MD5: 4699c28e56ed26a17069295c08c01a42
SHA-256: 2749312abbabe0799fe561ae6310fdee1b051ce78acb34ae688cd68cf4e9cbbf
Size: 127.07 kB - 389-ds-base-libs-2.8.0-9.el9_8.x86_64.rpm
MD5: b0fa04cb1636226caefe77636bc700c9
SHA-256: ac5620254a1cca5e031fdd6a2c13973af7d742102a093e54da89a0181689c0a4
Size: 1.51 MB - 389-ds-base-snmp-2.8.0-9.el9_8.x86_64.rpm
MD5: bfd28697b58f3edb5012dc00322ced76
SHA-256: df9c70a7ec432f451df90dd449018b8f39d3b59ab1413b6144e06d816f6169dc
Size: 49.30 kB - python3-lib389-2.8.0-9.el9_8.noarch.rpm
MD5: 5b64bf96cfbe4af4ffd4cd7174116b77
SHA-256: d54f99449668bf7c4dc8a80ddbbdc5bdb6a54fb550d9caf78a7d4c8f7cc9f071
Size: 1.10 MB