Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:21691-1

Опубликовано: 30 авг. 2026
Источник: suse-cvrf

Описание

Security update for 389-ds

This update for 389-ds fixes the following issues:

Update to version 3.0.6~git382.7a51ea5f5.

Security issues fixed:

  • CVE-2026-11610: heap buffer overflow in the SASL I/O layer via a crafted oversized LDAP UNBIND packet (bsc#1270695).
  • CVE-2026-11611: unbounded memory growth allowed by the Content Synchronization persistent search plugin when an authenticated client stops reading sync responses (bsc#1267975).
  • CVE-2026-11774: integer overflow in the SASL I/O layer leading to heap buffer overflow via crafted SASL packet length prefixes (bsc#1268298).
  • CVE-2026-11785: type confusion in the SSO token handler can cause partial stack address information disclosure in LDAP responses to authenticated users (bsc#1268065).
  • CVE-2026-11786: out-of-bounds read in the LDIF parser when processing attribute types with trailing semicolons during database import (bsc#1268064).
  • CVE-2026-11787: heap buffer overread due to missing checks in string filter parsing (bsc#1268062).
  • CVE-2026-11788: server crash due to missing allocation failure checks in the dereference control plugin (bsc#1268057).
  • CVE-2026-11789: integer underflow in the SMD5 password storage plugin leading to a buffer overflow via a crafted password hash (bsc#1268058).
  • CVE-2026-11790: excessive CPU consumption during authentication due to improper upper bounds enforcement in the PBKDF2-SHA256 password storage plugin (bsc#1268060).
  • CVE-2026-11791: use-after-free in the schema reload mechanism can be triggered while concurrent LDAP query traffic is active (bsc#1268047).
  • CVE-2026-11792: heap buffer overflow when audit logging is enabled and short cleartext passwords are logged (bsc#1268046).
  • CVE-2026-11793: stack buffer overflow leading to crash via crafted credentials with an oversized algorithm ID (bsc#1268041).
  • CVE-2026-11884: heap buffer overflow leading to crash when serializing objectclass definitions (bsc#1268115).
  • CVE-2026-12528: heap buffer overflow during ACI parsing via malformed ACI strings (bsc#1268491).

Other updates and bugfixes:

  • Version 3.0.6~git382.7a51ea5f5:

    • Issue 7711 - Fix typo in accountpolicy --login-history-size help text (#7713)
    • Issue 7688 - BUG - partial address leak in sso token (#7689)
    • Issue 7705 - With memberOfEntryScope set, deferred memberOf skips MODIFY operations (#7706)
    • Issue 7698 - Fix silent entry loss in LMDB bulk import waiter handling (#7699)
    • Issue 7666 - Replication performance degradation during total init on high-latency storage (#7667)
    • Issue 7201 - Syscall overhead in LMDB import writer thread (#7204)
    • Issue 7645 - Add runtime LeakSanitizer leak check (#7646)
    • Issue 7714 - UI - sass import rules are deprecated
    • Issue 7658 - Heap Buffer Overflow in sasl_io_recv() via Padded SASL UNBIND
    • Issue 7710 - MemberOf deferred update - Use condvar instead of sleep loop
    • Issue 7637 - UI - Using Arrow Keys in New Object Wizard Resulted in DOM Reload
    • Issue 7578 - schema - attribute refcount is not maintained properly
    • Issue 7605 - Harden CI test ports against ephemeral allocation (#7692)
    • Issue 7528 - Retry the CI image pull instead of failing the job (#7691)
    • Backport Issue 7519 -- ignore obsolete entrydn when entryrdn is in use (#7657)
    • Issue 7460 - MOD_REPLACE on groups/link attributes modifies overlap targets (#7461)
    • Issue 7505 - RFE - CLI - add feature to determine which password policy applies to a user
    • Issue 7670 - BDB range searches intermittently fail with err=1 under write load (#7671)
    • Issue 7108 - Fix shutdown crash in entry cache destruction (#7163)
    • Issue 7284 - Creating local password policy succeeds with incorrect passwordInHistory value (#7662)
    • Issue 7284 - Automated test for creating local password policy with incorrect passwordInHistory value (#7608)
    • Issue 7200 - repl-agmt create doesn't set some parameters (#7663)
    • Issue 7573 - Post-import cache autotuning does not recompute entry cache size (#7574)
  • Version 3.0.6~git359.953dc780a:

    • Issue 7470 - dsctl localhost tls import-server-key-cert fails with 'expected str, bytes or os.PathLike object, not NoneType' (#7477)
  • Version 3.0.6~git356.e6c148b60:

    • Issue 7611 - PBKDF2 password verification should reject invalid iteration count (#7613)
    • Issue 7558 - Total init sends the suffix entry twice (#7640)
    • Issue 7635 - Integer Underflow in {SMD5} Password Comparison (#7636)
    • Issue 7406 - Fix ldap-agent SNMP stats file loading (#7630)
    • Issue 7621 - Stack Buffer Overflow in Password checkPrefix
    • Issue 7623 - Heap Buffer Overflow in 389-ds-base Audit Log Password Masking
    • Issue 7602 - CI - lib389 user compare fails due to parentid mismatch (#7603)
    • Issue 7537 - CI - Fix replication log monitoring parser/timing failures (#7592)
    • Issue 7593 - Fix testimony docstring for SASL overflow test (#7606)
    • Issue 7530 - CI - Stabilize DNA plugin replication tests timing out in CI (#7572)
    • Issue 7593 - Reject invalid SASL packet length values in sasl_io_start_packet (#7594)
    • Issue 3555 - UI - Fix audit issue with npm - ws, js-yaml, babel/core (#7599)
    • Bump fast-uri from 3.1.0 to 3.1.2 in /src/cockpit/389-console (#7487)
    • Update dependency uuid to v14 [SECURITY] (#7456)
    • Update cockpit-389-ds-npm (major) (#7448)
    • Issue 7263 - UI - Use cockpit.file API for temporary file writes (#7590)
    • Issue 7541 - Add invalid ACL text header regression test (#7591)
    • Issue 7554 - UI - Revise local password policy layout
    • Issue 7521 - UI - make changes for cockpit API updates

Список пакетов

openSUSE Leap 16.0
389-ds-3.0.6~git382.7a51ea5f5-160000.1.1
389-ds-devel-3.0.6~git382.7a51ea5f5-160000.1.1
389-ds-snmp-3.0.6~git382.7a51ea5f5-160000.1.1
lib389-3.0.6~git382.7a51ea5f5-160000.1.1
libsvrcore0-3.0.6~git382.7a51ea5f5-160000.1.1

Описание

A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). After a successful SASL bind with integrity protection (SSF > 0), an authenticated attacker can send a specially crafted oversized LDAP UNBIND packet that is copied into a 512-byte heap receive buffer without a bounds check in sasl_io_recv() in sasl_io.c. This allows up to approximately 2 megabytes of attacker-controlled data to overflow the buffer, causing a denial of service (server crash). In FreeIPA and Red Hat Identity Management deployments, any domain user with a valid Kerberos ticket, any enrolled host, or any service account can trigger this vulnerability over the network after authenticating via GSSAPI. The vulnerable code path has existed since approximately 2013 (389-ds-base 1.3.2) and was not addressed by the CVE-2025-14905 fix, which patched a separate heap overflow in schema.c only.


Затронутые продукты
openSUSE Leap 16.0:389-ds-3.0.6~git382.7a51ea5f5-160000.1.1
openSUSE Leap 16.0:389-ds-devel-3.0.6~git382.7a51ea5f5-160000.1.1
openSUSE Leap 16.0:389-ds-snmp-3.0.6~git382.7a51ea5f5-160000.1.1
openSUSE Leap 16.0:lib389-3.0.6~git382.7a51ea5f5-160000.1.1

Ссылки

Описание

A flaw was found in 389 Directory Server. The Content Synchronization persistent search plugin allows unbounded memory growth when an authenticated client stops reading sync responses, enabling denial of service. Additional race conditions in plugin thread lifecycle can cause crashes during connection teardown or shutdown.


Затронутые продукты
openSUSE Leap 16.0:389-ds-3.0.6~git382.7a51ea5f5-160000.1.1
openSUSE Leap 16.0:389-ds-devel-3.0.6~git382.7a51ea5f5-160000.1.1
openSUSE Leap 16.0:389-ds-snmp-3.0.6~git382.7a51ea5f5-160000.1.1
openSUSE Leap 16.0:lib389-3.0.6~git382.7a51ea5f5-160000.1.1

Ссылки

Описание

An integer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), adding sizeof(uint32_t) to a crafted SASL packet length prefix of 0xFFFFFFFC causes unsigned wraparound to zero, bypassing the nsslapd-maxsasliosize limit and leading to a heap buffer overflow of up to approximately 2 megabytes of attacker-controlled data. After a successful SASL bind with integrity protection (SSF > 0), a remote attacker can cause a Denial of Service (DoS) or achieve Remote Code Execution (RCE). In FreeIPA and Red Hat Identity Management deployments, any domain user with a valid Kerberos ticket, enrolled host, or service account can trigger this vulnerability over the network. This flaw is independent of CVE-2025-14905, which patched schema.c only and did not modify sasl_io.c.


Затронутые продукты
openSUSE Leap 16.0:389-ds-3.0.6~git382.7a51ea5f5-160000.1.1
openSUSE Leap 16.0:389-ds-devel-3.0.6~git382.7a51ea5f5-160000.1.1
openSUSE Leap 16.0:389-ds-snmp-3.0.6~git382.7a51ea5f5-160000.1.1
openSUSE Leap 16.0:lib389-3.0.6~git382.7a51ea5f5-160000.1.1

Ссылки

Описание

A flaw was found in 389 Directory Server. A type confusion in the SSO token extended operation handler causes partial stack address information to be disclosed in LDAP responses to authenticated users.


Затронутые продукты
openSUSE Leap 16.0:389-ds-3.0.6~git382.7a51ea5f5-160000.1.1
openSUSE Leap 16.0:389-ds-devel-3.0.6~git382.7a51ea5f5-160000.1.1
openSUSE Leap 16.0:389-ds-snmp-3.0.6~git382.7a51ea5f5-160000.1.1
openSUSE Leap 16.0:lib389-3.0.6~git382.7a51ea5f5-160000.1.1

Ссылки

Описание

A flaw was found in 389 Directory Server. The LDIF parser reads past the end of a heap buffer when processing attribute types with trailing semicolons during database import, causing an out-of-bounds read detectable under memory instrumentation.


Затронутые продукты
openSUSE Leap 16.0:389-ds-3.0.6~git382.7a51ea5f5-160000.1.1
openSUSE Leap 16.0:389-ds-devel-3.0.6~git382.7a51ea5f5-160000.1.1
openSUSE Leap 16.0:389-ds-snmp-3.0.6~git382.7a51ea5f5-160000.1.1
openSUSE Leap 16.0:lib389-3.0.6~git382.7a51ea5f5-160000.1.1

Ссылки

Описание

A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads bytes before the start of a buffer without bounds checking, causing a heap buffer over-read in string filter parsing that may influence internal filter processing behavior.


Затронутые продукты
openSUSE Leap 16.0:389-ds-3.0.6~git382.7a51ea5f5-160000.1.1
openSUSE Leap 16.0:389-ds-devel-3.0.6~git382.7a51ea5f5-160000.1.1
openSUSE Leap 16.0:389-ds-snmp-3.0.6~git382.7a51ea5f5-160000.1.1
openSUSE Leap 16.0:lib389-3.0.6~git382.7a51ea5f5-160000.1.1

Ссылки

Описание

A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing an unauthenticated remote attacker to crash the LDAP server when the system is under memory pressure.


Затронутые продукты
openSUSE Leap 16.0:389-ds-3.0.6~git382.7a51ea5f5-160000.1.1
openSUSE Leap 16.0:389-ds-devel-3.0.6~git382.7a51ea5f5-160000.1.1
openSUSE Leap 16.0:389-ds-snmp-3.0.6~git382.7a51ea5f5-160000.1.1
openSUSE Leap 16.0:lib389-3.0.6~git382.7a51ea5f5-160000.1.1

Ссылки

Описание

A flaw was found in 389 Directory Server. The SMD5 password storage plugin performs unsigned integer underflow when computing salt length from a crafted password hash shorter than 16 bytes, causing a buffer over-read that crashes the LDAP server during authentication.


Затронутые продукты
openSUSE Leap 16.0:389-ds-3.0.6~git382.7a51ea5f5-160000.1.1
openSUSE Leap 16.0:389-ds-devel-3.0.6~git382.7a51ea5f5-160000.1.1
openSUSE Leap 16.0:389-ds-snmp-3.0.6~git382.7a51ea5f5-160000.1.1
openSUSE Leap 16.0:lib389-3.0.6~git382.7a51ea5f5-160000.1.1

Ссылки

Описание

A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password storage plugin does not enforce an upper bound on the iteration count extracted from stored password hashes. A privileged attacker who can modify a user's password hash can cause excessive CPU consumption during authentication, resulting in denial of service.


Затронутые продукты
openSUSE Leap 16.0:389-ds-3.0.6~git382.7a51ea5f5-160000.1.1
openSUSE Leap 16.0:389-ds-devel-3.0.6~git382.7a51ea5f5-160000.1.1
openSUSE Leap 16.0:389-ds-snmp-3.0.6~git382.7a51ea5f5-160000.1.1
openSUSE Leap 16.0:lib389-3.0.6~git382.7a51ea5f5-160000.1.1

Ссылки

Описание

A flaw was found in 389 Directory Server. During schema reload, the attr_syntax_swap_ht() function unconditionally frees attribute syntax information nodes, bypassing the refcount-based deferred deletion used elsewhere in the attribute syntax subsystem. If an administrator triggers schema reload while concurrent LDAP query traffic is active, worker threads may access freed memory, resulting in use-after-free or double-free and a denial of service (server crash).


Затронутые продукты
openSUSE Leap 16.0:389-ds-3.0.6~git382.7a51ea5f5-160000.1.1
openSUSE Leap 16.0:389-ds-devel-3.0.6~git382.7a51ea5f5-160000.1.1
openSUSE Leap 16.0:389-ds-snmp-3.0.6~git382.7a51ea5f5-160000.1.1
openSUSE Leap 16.0:lib389-3.0.6~git382.7a51ea5f5-160000.1.1

Ссылки

Описание

A heap buffer overflow flaw was found in 389 Directory Server. When audit logging is enabled, the create_masked_entry_string() function in auditlog.c copies a fixed-length password mask into a precisely-sized heap buffer without checking available space. If a short cleartext password is logged (requiring non-default CLEAR password storage or a compromised replication peer), the copy overflows the buffer, corrupting heap memory and audit log output.


Затронутые продукты
openSUSE Leap 16.0:389-ds-3.0.6~git382.7a51ea5f5-160000.1.1
openSUSE Leap 16.0:389-ds-devel-3.0.6~git382.7a51ea5f5-160000.1.1
openSUSE Leap 16.0:389-ds-snmp-3.0.6~git382.7a51ea5f5-160000.1.1
openSUSE Leap 16.0:lib389-3.0.6~git382.7a51ea5f5-160000.1.1

Ссылки

Описание

A stack buffer overflow flaw was found in 389 Directory Server. The checkPrefix() function in pw.c copies an attacker-controlled algorithm ID into a 256-byte stack buffer without bounds checking when parsing reversible-encrypted attribute values. An attacker with Directory Manager privileges can crash the LDAP server by storing a crafted credential with an oversized algorithm ID. FORTIFY_SOURCE mitigates this to denial of service only.


Затронутые продукты
openSUSE Leap 16.0:389-ds-3.0.6~git382.7a51ea5f5-160000.1.1
openSUSE Leap 16.0:389-ds-devel-3.0.6~git382.7a51ea5f5-160000.1.1
openSUSE Leap 16.0:389-ds-snmp-3.0.6~git382.7a51ea5f5-160000.1.1
openSUSE Leap 16.0:lib389-3.0.6~git382.7a51ea5f5-160000.1.1

Ссылки

Описание

A heap buffer overflow flaw was found in 389 Directory Server. When serializing objectclass definitions, the oc_superior (SUP) field length is omitted from buffer size calculations in read_schema_dse() and schema_oc_to_string(), but the field is still written via strcat(). An attacker with Directory Manager privileges, or a compromised replication supplier, can trigger a server crash by creating objectclasses with long SUP values. This is an incomplete fix variant of CVE-2025-14905.


Затронутые продукты
openSUSE Leap 16.0:389-ds-3.0.6~git382.7a51ea5f5-160000.1.1
openSUSE Leap 16.0:389-ds-devel-3.0.6~git382.7a51ea5f5-160000.1.1
openSUSE Leap 16.0:389-ds-snmp-3.0.6~git382.7a51ea5f5-160000.1.1
openSUSE Leap 16.0:lib389-3.0.6~git382.7a51ea5f5-160000.1.1

Ссылки

Описание

A flaw was found in 389 Directory Server in the __aclp__normalize_acltxt() function of aclparse.c. A malformed ACI (Access Control Instruction) string can trigger heap-buffer-overflow writes and reads during ACI parsing. The function fails to validate that the ACI keyword has sufficient length after whitespace stripping, leading to a 1-byte out-of-bounds write and subsequent out-of-bounds reads. An authenticated user with write access to the aci attribute could send a crafted ACI value to silently corrupt heap memory in the directory server process.


Затронутые продукты
openSUSE Leap 16.0:389-ds-3.0.6~git382.7a51ea5f5-160000.1.1
openSUSE Leap 16.0:389-ds-devel-3.0.6~git382.7a51ea5f5-160000.1.1
openSUSE Leap 16.0:389-ds-snmp-3.0.6~git382.7a51ea5f5-160000.1.1
openSUSE Leap 16.0:lib389-3.0.6~git382.7a51ea5f5-160000.1.1

Ссылки