[CLSA-2026:1787306784] 389-ds-base: Fix of 3 CVEs
Type:
security
Severity:
Important
Release date:
2026-08-21 10:06:36 UTC
Description:
- CVE-2026-11770: require an authorised replication bind DN for the CleanAllRUV extended operations and reject unexpected filters in the check-status payload - CVE-2026-11788: check the result of ber_init() before use in the deref control plugin to avoid a NULL pointer dereference - CVE-2026-15722: bound the replica id copy in get_ruvelement_from_berval to prevent a stack buffer overflow
Updated packages:
  • 389-ds-base-2.6.1-12.el9_6.tuxcare.els4.x86_64.rpm
    sha:7c73471f8e07e4bdee0c325868ee34c2489cf4bf038a17e85e4bef7d095dd04a
  • 389-ds-base-devel-2.6.1-12.el9_6.tuxcare.els4.x86_64.rpm
    sha:c54e0af60d79bda9a8fdf088a5e5ad4abbe6f97eb58aa185f98b3b8b284441d0
  • 389-ds-base-libs-2.6.1-12.el9_6.tuxcare.els4.x86_64.rpm
    sha:e38043bff636cd478c8bbd428a498d6b0c0878a98817eecdc648854005c634c2
  • 389-ds-base-snmp-2.6.1-12.el9_6.tuxcare.els4.x86_64.rpm
    sha:d6cb2d2d6598884744a836056789433f843a1b09caeafdcb34d65848deafa307
  • python3-lib389-2.6.1-12.el9_6.tuxcare.els4.noarch.rpm
    sha:b5a71432712068c14454e13cedeeb187311bbbbf458fe8509640bf2f8757d854
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.