gpp_maybe
Security update for 389-ds
SUSE-SLE-Module-Server-Applications-15-SP7-2026-3678
This update for 389-ds fixes the following issues: - CVE-2026-11774: integer overflow in SASL packet length bypasses size limit leading to heap buffer overflow (bsc#1268298). - CVE-2026-11785: type confusion in the SSO token handler can cause partial stack address information disclosure (bsc#1268065). - CVE-2026-11786: lack of length check can cause an out-of-bound read (bsc#1268064). - CVE-2026-11791: schema reload triggered during concurrent LDAP query traffic can lead to a use-after-free (bsc#1268047). Changes for 389-ds: - Update to version 2.7.0~git234.0afa2e38b: * Issue 7711 - Fix typo in accountpolicy --login-history-size help text (#7713) * Issue 7688 - BUG - partial address leak in sso token (#7689) * Issue 7705 - With memberOfEntryScope set, deferred memberOf skips MODIFY operations (#7706) * Issue 7714 - UI - sass import rules are deprecated * Issue 7658 - Heap Buffer Overflow in sasl_io_recv() via Padded SASL UNBIND * Issue 7710 - MemberOf deferred update - Use condvar instead of sleep loop * Issue 7637 - fix cherry-pick error * Issue 7637 - UI - Using Arrow Keys in New Object Wizard Resulted in DOM Reload * Issue 7578 - schema - attribute refcount is not maintained properly * Issue 7605 - Harden CI test ports against ephemeral allocation (#7692) * Issue 7528 - Retry the CI image pull instead of failing the job (#7691) * Issue 7460 - MOD_REPLACE on groups/link attributes modifies overlap targets (#7461) * Issue 7670 - BDB range searches intermittently fail with err=1 under write load (#7671) * Issue 7108 - Fix shutdown crash in entry cache destruction (#7163) * Issue 7284 - Creating local password policy succeeds with incorrect passwordInHistory value (#7662) * Issue 7284 - Automated test for creating local password policy with incorrect passwordInHistory value (#7608) * Issue 7519 - Ignore obsolete entrydn index when entryrdn is enabled (#7526) * Issue 7611 - Preserve legacy PBKDF2 hash compatibility (#7649) * Issue 7547 - Heap buffer overflow in ldap_utf8prev() * Issue 7611 - PBKDF2 password verification should reject invalid iteration count (#7613) * Issue 7558 - Total init sends the suffix entry twice (#7640) * Issue 7635 - Integer Underflow in {SMD5} Password Comparison (#7636)
-
Release DateAug 21 2026
-
ReferencesBugzilla: 1268047, 1268064, 1268065, 1268298
CVEs: CVE-2026-11774, CVE-2026-11785, CVE-2026-11786, CVE-2026-11791 -
Typesecurity
-
Severityimportant
cloud_download Downloads
Server Applications Module 15.7 aarch64
-
Packages389-ds
389 Directory Server389-ds-devel2.7.0~git234.0afa2e38b-150700.3.22.1 lock rpm lock src
Development files for the 389 Directory Serverlib3892.7.0~git234.0afa2e38b-150700.3.22.1 lock rpm
389 Directory Server administration tools and librarylibsvrcore02.7.0~git234.0afa2e38b-150700.3.22.1 lock rpm
Secure PIN handling using NSS crypto2.7.0~git234.0afa2e38b-150700.3.22.1 lock rpm
Server Applications Module 15.7 ppc64le
-
Packages389-ds
389 Directory Server389-ds-devel2.7.0~git234.0afa2e38b-150700.3.22.1 lock rpm lock src
Development files for the 389 Directory Serverlib3892.7.0~git234.0afa2e38b-150700.3.22.1 lock rpm
389 Directory Server administration tools and librarylibsvrcore02.7.0~git234.0afa2e38b-150700.3.22.1 lock rpm
Secure PIN handling using NSS crypto2.7.0~git234.0afa2e38b-150700.3.22.1 lock rpm
Server Applications Module 15.7 x86_64
-
Packages389-ds
389 Directory Server389-ds-devel2.7.0~git234.0afa2e38b-150700.3.22.1 lock rpm lock src
Development files for the 389 Directory Serverlib3892.7.0~git234.0afa2e38b-150700.3.22.1 lock rpm
389 Directory Server administration tools and librarylibsvrcore02.7.0~git234.0afa2e38b-150700.3.22.1 lock rpm
Secure PIN handling using NSS crypto2.7.0~git234.0afa2e38b-150700.3.22.1 lock rpm
Server Applications Module 15.7 s390x
-
Packages389-ds
389 Directory Server389-ds-devel2.7.0~git234.0afa2e38b-150700.3.22.1 lock rpm lock src
Development files for the 389 Directory Serverlib3892.7.0~git234.0afa2e38b-150700.3.22.1 lock rpm
389 Directory Server administration tools and librarylibsvrcore02.7.0~git234.0afa2e38b-150700.3.22.1 lock rpm
Secure PIN handling using NSS crypto2.7.0~git234.0afa2e38b-150700.3.22.1 lock rpm