{"id":"SUSE-SU-2026:3136-1","summary":"Security update for 389-ds","details":"This update for 389-ds fixes the following issues:\n\nUpdate to version 2.2.10~git255.752643c78.\n\nSecurity issues fixed:\n\n- CVE-2026-11610: missing bounds check in `sasl_io_recv()` can lead to a heap buffer overflow when processing a\n  specially crafted oversized LDAP UNBIND packet (bsc#1270695).\n- CVE-2026-11611: Content Synchronization persistent search plugin allows unbounded memory growth when an authenticated\n  client stops reading sync responses(bsc#1267975).\n- CVE-2026-11774: integer overflow in `sasl_io_start_packet()` can lead to heap buffer overflow when processing a\n  crafted SASL packet length prefix (bsc#1268298).\n- CVE-2026-11785: type confusion in the SSO token handler can cause partial stack address information disclosure in\n  LDA responses (bsc#1268065).\n- CVE-2026-11786: out-of-bounds read in the LDIF parser when processing attribute types with trailing semicolons during\n  database import (bsc#1268064).\n- CVE-2026-11787: missing bounds check in the `ldap_utf8prev()` functioncan can lead to a heap buffer overread in\n  string filter parsing(bsc#1268062).\n- CVE-2026-11788: missing allocation check in the dereference control plugin  before using a BER structure can lead to\n  LDAP server crash when the system is under memory pressure (bsc#1268057).\n- CVE-2026-11789: integer underflow in the SMD5 password storage plugin can lead to a buffer overread when computing\n  salt length from a crafted password hash shorter than 16 bytes (bsc#1268058).\n- CVE-2026-11790: improper bounds enforcement in the BKDF2-SHA256 password storage plugin can lead to excessive\n  resource consumption during authentication and cause a DoS (bsc#1268060).\n- CVE-2026-11791: use-after-free in the schema reload mechanism can lead to a `ns-slapd` crash when concurrent LDAP\n  query traffic is active (bsc#1268047).\n- CVE-2026-11792: missing checks in `create_masked_entry_string` can lead to a heap and log output corruption whe a\n  short cleartext password is logged  (bsc#1268046).\n- CVE-2026-11793: missing bounds check in `checkPrefix()` can lead to a stack buffer overflow when processing an\n  algorithm ID during parsing of reversible-encrypted attribute values (bsc#1268041).\n- CVE-2026-11884: improper string management can lead to heap buffer overflow when serializing objectclass definitions\n  (bsc#1268115).\n- CVE-2026-12528: missing length checks in the `__aclp__normalize_acltxt()` function can lead to heap buffer overflow\n  when processing a malformed ACI string (bsc#1268491).\n\nOther updates and bugfixes:\n\n- Version 2.2.10~git255.752643c78.\n  * Issue 7406 - Fix `ldap-agent` SNMP stats file loading (#7630)\n  * Issue 7621 - Stack Buffer Overflow in Password `checkPrefix`\n  * Issue 7623 - Heap Buffer Overflow in `389-ds-base` Audit Log Password Masking\n  * Issue 6625 - Backport `get_pid` to fix `check_asan_report` (#7625)\n  * Issue 7602 - CI - `lib389` user compare fails due to parentid mismatch (#7603)\n  * Issue 7537 - CI - Fix replication log monitoring parser/timing failures (#7592)\n  * Issue 7593 - Fix testimony docstring for SASL overflow test (#7606)\n  * Issue 7530 - CI - Stabilize DNA plugin replication tests timing out in CI (#7572)\n  * Issue 7593 - Reject invalid SASL packet length values in `sasl_io_start_packet` (#7594)\n  * Issue 3555 - UI - Fix audit issue with `npm` - `ws`, `js-yaml`, `js-yaml` , `postcss`, `uuid`\n  * Issue 7541 - Add invalid ACL text header regression test (#7591)\n  * Issue 7541 - heap-buffer-overflows in `__aclp__normalize_acltxt()` (#7542)\n  * Issue 7576 - Fix leak of temporary attribute syntax hash tables after schema reload\n  * Issue 7558 - During online import, the IDL should be created with in-depth first approach (#7559)\n  * Issue 7500 - Prevent unsigned integer underflow during stalled import\n  * Issue 7560 - `lib389` - Add helper function for checking ASAN files\n  * Issue 7539 - Server shutdown during online reindex may lead to data loss (#7540)\n  * Issue 7549 - Substring index should validate minimum `nsSubStrBegin`/`nsSubStrEnd` values (#7550)\n  * Issue 7440 - Substring index produces empty results and can crash when non-default `nsSubStrBegin`/`nsSubStrEnd`\n    lengths are configured (#7441)\n  * Fix test389 imports on older branches\n  * Issue 7437 - `LeakSanitizer`: memory leaks in CoS cache error paths (#7438)\n  * Issue 6922 - `AddressSanitizer`: leaks found by acl test suite\n  * Issue 3555 - UI - Fix audit issue with `npm` - `brace-expansion` (#7556)\n  * Issue 7554 - deref plugin null pointer dereference if `ber_init` fails\n  * Issue 7514 - Crash when doing moddn on very large subtree\n  * Issue 7516 - `dblayer_bulk_nextdata` should not return an error when maxrecords is hit\n","modified":"2026-07-21T09:45:06.230434612Z","published":"2026-07-20T15:10:10Z","related":["CVE-2026-11610","CVE-2026-11611","CVE-2026-11774","CVE-2026-11785","CVE-2026-11786","CVE-2026-11787","CVE-2026-11788","CVE-2026-11789","CVE-2026-11790","CVE-2026-11791","CVE-2026-11792","CVE-2026-11793","CVE-2026-11884","CVE-2026-12528"],"upstream":["CVE-2026-11610","CVE-2026-11611","CVE-2026-11774","CVE-2026-11785","CVE-2026-11786","CVE-2026-11787","CVE-2026-11788","CVE-2026-11789","CVE-2026-11790","CVE-2026-11791","CVE-2026-11792","CVE-2026-11793","CVE-2026-11884","CVE-2026-12528"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20263136-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267975"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268041"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268046"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268047"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268057"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268058"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268060"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268062"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268064"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268065"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268115"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268298"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268491"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269120"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270695"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11610"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11611"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11774"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11785"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11786"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11787"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11788"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11789"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11790"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11791"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11792"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11793"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11884"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12528"}],"affected":[{"package":{"name":"389-ds","ecosystem":"SUSE:Linux Enterprise Server 15 SP6-LTSS","purl":"pkg:rpm/suse/389-ds&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.2.10~git255.752643c78-150600.8.32.1"}]}],"ecosystem_specific":{"binaries":[{"389-ds-devel":"2.2.10~git255.752643c78-150600.8.32.1","lib389":"2.2.10~git255.752643c78-150600.8.32.1","libsvrcore0":"2.2.10~git255.752643c78-150600.8.32.1","389-ds":"2.2.10~git255.752643c78-150600.8.32.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3136-1.json"}},{"package":{"name":"389-ds","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP6","purl":"pkg:rpm/suse/389-ds&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.2.10~git255.752643c78-150600.8.32.1"}]}],"ecosystem_specific":{"binaries":[{"lib389":"2.2.10~git255.752643c78-150600.8.32.1","libsvrcore0":"2.2.10~git255.752643c78-150600.8.32.1","389-ds":"2.2.10~git255.752643c78-150600.8.32.1","389-ds-devel":"2.2.10~git255.752643c78-150600.8.32.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3136-1.json"}}],"schema_version":"1.7.5"}