[CLSA-2026:1787336081] 389-ds-base: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2026-08-21 18:14:52 UTC
Description:
- CVE-2026-11788: null-check ber_init failure in the deref control parser - CVE-2026-11770: fix pre-auth LDAP filter injection in CleanAllRUV extended ops - Issue-6929-Compilation-failure-with-rust-1.89.patch: fix build: make the ValueArrayRefIter lifetime explicit for rust 1.89+
Updated packages:
  • 389-ds-base-2.2.4-5.el9_2.tuxcare.els8.x86_64.rpm
    sha:53e6a07dd9212a6b087756851ea6b5ad1a29b4b660711318aac40062a68406a5
  • 389-ds-base-devel-2.2.4-5.el9_2.tuxcare.els8.x86_64.rpm
    sha:1eb4f565fa238d949a4bb0446fc8a34996356054ea6278183855533cf0ca6574
  • 389-ds-base-libs-2.2.4-5.el9_2.tuxcare.els8.x86_64.rpm
    sha:419bd96b2db1264dec3d183c03f666fb7f344e532b669b3d25f837da8d288b2a
  • 389-ds-base-snmp-2.2.4-5.el9_2.tuxcare.els8.x86_64.rpm
    sha:d46074ffe3f494b8116d785a194e3c840220be393d2d9eb03b24fc9af89d0606
  • python3-lib389-2.2.4-5.el9_2.tuxcare.els8.noarch.rpm
    sha:be76a044a774b27518402a63c5d0ab772da73879dbc4289e63566eaf5b1df502
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.