{"id":"SUSE-SU-2026:3138-1","summary":"Security update for 389-ds","details":"This update for 389-ds fixes the following issues\n\n- Update to version 2.7.0~git212.9b0755edb.\n- CVE-2026-11610: heap buffer overflow in `sasl_io_recv()` via padded SASL UNBIND (bsc#1270695).\n- CVE-2026-11611: content synchronization persistent search plugin can allow unbounded memory growth (bsc#1267975).\n- CVE-2026-11774: integer overflow in SASL packet length bypasses size limit leading to heap buffer overflow\n  (bsc#1268298).\n- CVE-2026-11785: type confusion in the SSO token handler can cause partial stack address information disclosure\n  (bsc#1268065).\n- CVE-2026-11786: lack of length check can cause an out-of-bounds read (bsc#1268064).\n- CVE-2026-11787: lack of bounds check can lead to a heap buffer overread (bsc#1268062).\n- CVE-2026-11788: lack of allocation failure check can lead to NULL pointer dereference (bsc#1268057).\n- CVE-2026-11789: crafted SMD5 hash can lead to an integer underflow (bsc#1268058).\n- CVE-2026-11790: crafted password hash can cause excessive CPU consumption (bsc#1268060).\n- CVE-2026-11791: schema reload triggered during concurrent LDAP query traffic can lead to a use-after-free\n  (bsc#1268047).\n- CVE-2026-11792: password value shorter than 23 characters can cause a heap buffer overflow (bsc#1268046).\n- CVE-2026-11793: crafted `nsDS5ReplicaCredentials` can lead to a stack buffer overflow (bsc#1268041).\n- CVE-2026-11884: remote code execution and denial of service via heap buffer overflow (bsc#1268115).\n- CVE-2026-12528: heap buffer overflows in `__aclp__normalize_acltxt()` (bsc#1268491).\n","modified":"2026-07-21T09:45:06.280022189Z","published":"2026-07-20T15:10:54Z","related":["CVE-2026-11610","CVE-2026-11611","CVE-2026-11774","CVE-2026-11785","CVE-2026-11786","CVE-2026-11787","CVE-2026-11788","CVE-2026-11789","CVE-2026-11790","CVE-2026-11791","CVE-2026-11792","CVE-2026-11793","CVE-2026-11884","CVE-2026-12528"],"upstream":["CVE-2026-11610","CVE-2026-11611","CVE-2026-11774","CVE-2026-11785","CVE-2026-11786","CVE-2026-11787","CVE-2026-11788","CVE-2026-11789","CVE-2026-11790","CVE-2026-11791","CVE-2026-11792","CVE-2026-11793","CVE-2026-11884","CVE-2026-12528"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20263138-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267975"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268041"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268046"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268047"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268057"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268058"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268060"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268062"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268064"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268065"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268115"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268298"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268491"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269120"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270695"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11610"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11611"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11774"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11785"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11786"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11787"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11788"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11789"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11790"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11791"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11792"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11793"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11884"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12528"}],"affected":[{"package":{"name":"389-ds","ecosystem":"SUSE:Linux Enterprise Module for Server Applications 15 SP7","purl":"pkg:rpm/suse/389-ds&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.7.0~git212.9b0755edb-150700.3.19.1"}]}],"ecosystem_specific":{"binaries":[{"389-ds-devel":"2.7.0~git212.9b0755edb-150700.3.19.1","lib389":"2.7.0~git212.9b0755edb-150700.3.19.1","libsvrcore0":"2.7.0~git212.9b0755edb-150700.3.19.1","389-ds":"2.7.0~git212.9b0755edb-150700.3.19.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3138-1.json"}}],"schema_version":"1.7.5"}