Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:3137-1

Опубликовано: 20 июл. 2026
Источник: suse-cvrf

Описание

Security update for 389-ds

This update for 389-ds fixes the following issues:

Update to version 2.2.10~git255.752643c78.

Security issues fixed:

  • CVE-2026-11610: missing bounds check in sasl_io_recv() can lead to a heap buffer overflow when processing a specially crafted oversized LDAP UNBIND packet (bsc#1270695).
  • CVE-2026-11611: Content Synchronization persistent search plugin allows unbounded memory growth when an authenticated client stops reading sync responses(bsc#1267975).
  • CVE-2026-11774: integer overflow in sasl_io_start_packet() can lead to heap buffer overflow when processing a crafted SASL packet length prefix (bsc#1268298).
  • CVE-2026-11785: type confusion in the SSO token handler can cause partial stack address information disclosure in LDA responses (bsc#1268065).
  • CVE-2026-11786: out-of-bounds read in the LDIF parser when processing attribute types with trailing semicolons during database import (bsc#1268064).
  • CVE-2026-11787: missing bounds check in the ldap_utf8prev() functioncan can lead to a heap buffer overread in string filter parsing(bsc#1268062).
  • CVE-2026-11788: missing allocation check in the dereference control plugin before using a BER structure can lead to LDAP server crash when the system is under memory pressure (bsc#1268057).
  • CVE-2026-11789: integer underflow in the SMD5 password storage plugin can lead to a buffer overread when computing salt length from a crafted password hash shorter than 16 bytes (bsc#1268058).
  • CVE-2026-11790: improper bounds enforcement in the BKDF2-SHA256 password storage plugin can lead to excessive resource consumption during authentication and cause a DoS (bsc#1268060).
  • CVE-2026-11791: use-after-free in the schema reload mechanism can lead to a ns-slapd crash when concurrent LDAP query traffic is active (bsc#1268047).
  • CVE-2026-11792: missing checks in create_masked_entry_string can lead to a heap and log output corruption whe a short cleartext password is logged (bsc#1268046).
  • CVE-2026-11793: missing bounds check in checkPrefix() can lead to a stack buffer overflow when processing an algorithm ID during parsing of reversible-encrypted attribute values (bsc#1268041).
  • CVE-2026-11884: improper string management can lead to heap buffer overflow when serializing objectclass definitions (bsc#1268115).
  • CVE-2026-12528: missing length checks in the __aclp__normalize_acltxt() function can lead to heap buffer overflow when processing a malformed ACI string (bsc#1268491).

Other updates and bugfixes:

  • Version 2.2.10~git255.752643c78.
    • Issue 7406 - Fix ldap-agent SNMP stats file loading (#7630)
    • Issue 7621 - Stack Buffer Overflow in Password checkPrefix
    • Issue 7623 - Heap Buffer Overflow in 389-ds-base Audit Log Password Masking
    • Issue 6625 - Backport get_pid to fix check_asan_report (#7625)
    • Issue 7602 - CI - lib389 user compare fails due to parentid mismatch (#7603)
    • Issue 7537 - CI - Fix replication log monitoring parser/timing failures (#7592)
    • Issue 7593 - Fix testimony docstring for SASL overflow test (#7606)
    • Issue 7530 - CI - Stabilize DNA plugin replication tests timing out in CI (#7572)
    • Issue 7593 - Reject invalid SASL packet length values in sasl_io_start_packet (#7594)
    • Issue 3555 - UI - Fix audit issue with npm - ws, js-yaml, js-yaml , postcss, uuid
    • Issue 7541 - Add invalid ACL text header regression test (#7591)
    • Issue 7541 - heap-buffer-overflows in __aclp__normalize_acltxt() (#7542)
    • Issue 7576 - Fix leak of temporary attribute syntax hash tables after schema reload
    • Issue 7558 - During online import, the IDL should be created with in-depth first approach (#7559)
    • Issue 7500 - Prevent unsigned integer underflow during stalled import
    • Issue 7560 - lib389 - Add helper function for checking ASAN files
    • Issue 7539 - Server shutdown during online reindex may lead to data loss (#7540)
    • Issue 7549 - Substring index should validate minimum nsSubStrBegin/nsSubStrEnd values (#7550)
    • Issue 7440 - Substring index produces empty results and can crash when non-default nsSubStrBegin/nsSubStrEnd lengths are configured (#7441)
    • Fix test389 imports on older branches
    • Issue 7437 - LeakSanitizer: memory leaks in CoS cache error paths (#7438)
    • Issue 6922 - AddressSanitizer: leaks found by acl test suite
    • Issue 3555 - UI - Fix audit issue with npm - brace-expansion (#7556)
    • Issue 7554 - deref plugin null pointer dereference if ber_init fails
    • Issue 7514 - Crash when doing moddn on very large subtree
    • Issue 7516 - dblayer_bulk_nextdata should not return an error when maxrecords is hit

Список пакетов

SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS
389-ds-2.2.10~git255.752643c78-150500.3.48.1
389-ds-devel-2.2.10~git255.752643c78-150500.3.48.1
lib389-2.2.10~git255.752643c78-150500.3.48.1
libsvrcore0-2.2.10~git255.752643c78-150500.3.48.1
SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS
389-ds-2.2.10~git255.752643c78-150500.3.48.1
389-ds-devel-2.2.10~git255.752643c78-150500.3.48.1
lib389-2.2.10~git255.752643c78-150500.3.48.1
libsvrcore0-2.2.10~git255.752643c78-150500.3.48.1
SUSE Linux Enterprise Server 15 SP5-LTSS
389-ds-2.2.10~git255.752643c78-150500.3.48.1
389-ds-devel-2.2.10~git255.752643c78-150500.3.48.1
lib389-2.2.10~git255.752643c78-150500.3.48.1
libsvrcore0-2.2.10~git255.752643c78-150500.3.48.1
SUSE Linux Enterprise Server for SAP Applications 15 SP5
389-ds-2.2.10~git255.752643c78-150500.3.48.1
389-ds-devel-2.2.10~git255.752643c78-150500.3.48.1
lib389-2.2.10~git255.752643c78-150500.3.48.1
libsvrcore0-2.2.10~git255.752643c78-150500.3.48.1

Описание

A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). After a successful SASL bind with integrity protection (SSF > 0), an authenticated attacker can send a specially crafted oversized LDAP UNBIND packet that is copied into a 512-byte heap receive buffer without a bounds check in sasl_io_recv() in sasl_io.c. This allows up to approximately 2 megabytes of attacker-controlled data to overflow the buffer, causing a denial of service (server crash). In FreeIPA and Red Hat Identity Management deployments, any domain user with a valid Kerberos ticket, any enrolled host, or any service account can trigger this vulnerability over the network after authenticating via GSSAPI. The vulnerable code path has existed since approximately 2013 (389-ds-base 1.3.2) and was not addressed by the CVE-2025-14905 fix, which patched a separate heap overflow in schema.c only.


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:389-ds-2.2.10~git255.752643c78-150500.3.48.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:389-ds-devel-2.2.10~git255.752643c78-150500.3.48.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:lib389-2.2.10~git255.752643c78-150500.3.48.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:libsvrcore0-2.2.10~git255.752643c78-150500.3.48.1

Ссылки

Описание

A flaw was found in 389 Directory Server. The Content Synchronization persistent search plugin allows unbounded memory growth when an authenticated client stops reading sync responses, enabling denial of service. Additional race conditions in plugin thread lifecycle can cause crashes during connection teardown or shutdown.


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:389-ds-2.2.10~git255.752643c78-150500.3.48.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:389-ds-devel-2.2.10~git255.752643c78-150500.3.48.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:lib389-2.2.10~git255.752643c78-150500.3.48.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:libsvrcore0-2.2.10~git255.752643c78-150500.3.48.1

Ссылки

Описание

An integer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), adding sizeof(uint32_t) to a crafted SASL packet length prefix of 0xFFFFFFFC causes unsigned wraparound to zero, bypassing the nsslapd-maxsasliosize limit and leading to a heap buffer overflow of up to approximately 2 megabytes of attacker-controlled data. After a successful SASL bind with integrity protection (SSF > 0), a remote attacker can cause a Denial of Service (DoS) or achieve Remote Code Execution (RCE). In FreeIPA and Red Hat Identity Management deployments, any domain user with a valid Kerberos ticket, enrolled host, or service account can trigger this vulnerability over the network. This flaw is independent of CVE-2025-14905, which patched schema.c only and did not modify sasl_io.c.


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:389-ds-2.2.10~git255.752643c78-150500.3.48.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:389-ds-devel-2.2.10~git255.752643c78-150500.3.48.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:lib389-2.2.10~git255.752643c78-150500.3.48.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:libsvrcore0-2.2.10~git255.752643c78-150500.3.48.1

Ссылки

Описание

A flaw was found in 389 Directory Server. A type confusion in the SSO token extended operation handler causes partial stack address information to be disclosed in LDAP responses to authenticated users.


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:389-ds-2.2.10~git255.752643c78-150500.3.48.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:389-ds-devel-2.2.10~git255.752643c78-150500.3.48.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:lib389-2.2.10~git255.752643c78-150500.3.48.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:libsvrcore0-2.2.10~git255.752643c78-150500.3.48.1

Ссылки

Описание

A flaw was found in 389 Directory Server. The LDIF parser reads past the end of a heap buffer when processing attribute types with trailing semicolons during database import, causing an out-of-bounds read detectable under memory instrumentation.


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:389-ds-2.2.10~git255.752643c78-150500.3.48.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:389-ds-devel-2.2.10~git255.752643c78-150500.3.48.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:lib389-2.2.10~git255.752643c78-150500.3.48.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:libsvrcore0-2.2.10~git255.752643c78-150500.3.48.1

Ссылки

Описание

A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads bytes before the start of a buffer without bounds checking, causing a heap buffer over-read in string filter parsing that may influence internal filter processing behavior.


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:389-ds-2.2.10~git255.752643c78-150500.3.48.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:389-ds-devel-2.2.10~git255.752643c78-150500.3.48.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:lib389-2.2.10~git255.752643c78-150500.3.48.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:libsvrcore0-2.2.10~git255.752643c78-150500.3.48.1

Ссылки

Описание

A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing an unauthenticated remote attacker to crash the LDAP server when the system is under memory pressure.


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:389-ds-2.2.10~git255.752643c78-150500.3.48.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:389-ds-devel-2.2.10~git255.752643c78-150500.3.48.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:lib389-2.2.10~git255.752643c78-150500.3.48.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:libsvrcore0-2.2.10~git255.752643c78-150500.3.48.1

Ссылки

Описание

A flaw was found in 389 Directory Server. The SMD5 password storage plugin performs unsigned integer underflow when computing salt length from a crafted password hash shorter than 16 bytes, causing a buffer over-read that crashes the LDAP server during authentication.


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:389-ds-2.2.10~git255.752643c78-150500.3.48.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:389-ds-devel-2.2.10~git255.752643c78-150500.3.48.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:lib389-2.2.10~git255.752643c78-150500.3.48.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:libsvrcore0-2.2.10~git255.752643c78-150500.3.48.1

Ссылки

Описание

A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password storage plugin does not enforce an upper bound on the iteration count extracted from stored password hashes. A privileged attacker who can modify a user's password hash can cause excessive CPU consumption during authentication, resulting in denial of service.


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:389-ds-2.2.10~git255.752643c78-150500.3.48.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:389-ds-devel-2.2.10~git255.752643c78-150500.3.48.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:lib389-2.2.10~git255.752643c78-150500.3.48.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:libsvrcore0-2.2.10~git255.752643c78-150500.3.48.1

Ссылки

Описание

A flaw was found in 389 Directory Server. During schema reload, the attr_syntax_swap_ht() function unconditionally frees attribute syntax information nodes, bypassing the refcount-based deferred deletion used elsewhere in the attribute syntax subsystem. If an administrator triggers schema reload while concurrent LDAP query traffic is active, worker threads may access freed memory, resulting in use-after-free or double-free and a denial of service (server crash).


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:389-ds-2.2.10~git255.752643c78-150500.3.48.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:389-ds-devel-2.2.10~git255.752643c78-150500.3.48.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:lib389-2.2.10~git255.752643c78-150500.3.48.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:libsvrcore0-2.2.10~git255.752643c78-150500.3.48.1

Ссылки

Описание

A heap buffer overflow flaw was found in 389 Directory Server. When audit logging is enabled, the create_masked_entry_string() function in auditlog.c copies a fixed-length password mask into a precisely-sized heap buffer without checking available space. If a short cleartext password is logged (requiring non-default CLEAR password storage or a compromised replication peer), the copy overflows the buffer, corrupting heap memory and audit log output.


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:389-ds-2.2.10~git255.752643c78-150500.3.48.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:389-ds-devel-2.2.10~git255.752643c78-150500.3.48.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:lib389-2.2.10~git255.752643c78-150500.3.48.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:libsvrcore0-2.2.10~git255.752643c78-150500.3.48.1

Ссылки

Описание

A stack buffer overflow flaw was found in 389 Directory Server. The checkPrefix() function in pw.c copies an attacker-controlled algorithm ID into a 256-byte stack buffer without bounds checking when parsing reversible-encrypted attribute values. An attacker with Directory Manager privileges can crash the LDAP server by storing a crafted credential with an oversized algorithm ID. FORTIFY_SOURCE mitigates this to denial of service only.


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:389-ds-2.2.10~git255.752643c78-150500.3.48.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:389-ds-devel-2.2.10~git255.752643c78-150500.3.48.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:lib389-2.2.10~git255.752643c78-150500.3.48.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:libsvrcore0-2.2.10~git255.752643c78-150500.3.48.1

Ссылки

Описание

A heap buffer overflow flaw was found in 389 Directory Server. When serializing objectclass definitions, the oc_superior (SUP) field length is omitted from buffer size calculations in read_schema_dse() and schema_oc_to_string(), but the field is still written via strcat(). An attacker with Directory Manager privileges, or a compromised replication supplier, can trigger a server crash by creating objectclasses with long SUP values. This is an incomplete fix variant of CVE-2025-14905.


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:389-ds-2.2.10~git255.752643c78-150500.3.48.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:389-ds-devel-2.2.10~git255.752643c78-150500.3.48.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:lib389-2.2.10~git255.752643c78-150500.3.48.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:libsvrcore0-2.2.10~git255.752643c78-150500.3.48.1

Ссылки

Описание

A flaw was found in 389 Directory Server in the __aclp__normalize_acltxt() function of aclparse.c. A malformed ACI (Access Control Instruction) string can trigger heap-buffer-overflow writes and reads during ACI parsing. The function fails to validate that the ACI keyword has sufficient length after whitespace stripping, leading to a 1-byte out-of-bounds write and subsequent out-of-bounds reads. An authenticated user with write access to the aci attribute could send a crafted ACI value to silently corrupt heap memory in the directory server process.


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:389-ds-2.2.10~git255.752643c78-150500.3.48.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:389-ds-devel-2.2.10~git255.752643c78-150500.3.48.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:lib389-2.2.10~git255.752643c78-150500.3.48.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:libsvrcore0-2.2.10~git255.752643c78-150500.3.48.1

Ссылки
Уязвимость SUSE-SU-2026:3137-1