Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:21950-1

Опубликовано: 24 сент. 2026
Источник: suse-cvrf

Описание

Security update for 389-ds

This update for 389-ds fixes the following issues:

  • CVE-2026-11770: pre-auth LDAP filter injection in CleanAllRUV status check (bsc#1273133).
  • CVE-2026-18355: heap buffer overflow in the SASL I/O layer allows a remote authenticated attacker to cause a denial of service or potentially achieve remote code execution (bsc#1279864).
  • CVE-2026-18453: 389-ds-base: 389-ds-base: pre-authentication NULL pointer dereference via paged results and USE_ONE_BACKEND control in op_shared_search (bsc#1279572).
  • CVE-2026-18922: stale identity carried in a Cyrus SASL auxiliary property during SASL PLAIN authentication allows unauthenticated attackers to achieve privilege escalation to Directory Manager (bsc#1279865).
  • CVE-2026-19843: unescaped LDAP DN in Cockpit 389 Console LDAP editor allows an LDAP user with delegated privileges to execute shell commands with root privileges on the directory server host (bsc#1279866).
  • CVE-2026-76560: incorrect matching in the SELFDN ACI bind-rule evaluator allows an anonymous LDAP client to bypass access controls on directory entries containing empty SELFDN attributes (bsc#1279867).

Changes for 389-ds:

  • Update to version 3.0.7~git2.2846d5288:
  • Issue 7757 - stack-buffer-overflow caused by slapi_attr_init_syntax() (#7759)
  • Issue 7796 - A large received replicaID can overflow the storage buffer (#7797)
  • Issue 7041 - Add WebUI test for group member management (#7111)
  • Issue 7808 - CI - harden online_import_nosync_test (#7809)
  • Issue 7611 - PBKDF2 password verification should reject invalid iteration counts (#7632) (#7812)
  • [Backport 389-ds-base-3.0] Update rust-dependencies (#7799)
  • Issue 7595 - Remove the nightly dedup gate and fix dispatched test runs
  • Fix expiration time check (#7718)
  • Issue 7774 - Add backport action (#7775)
  • Issue 7770 - Testimony failure in test_cleanruv_extop_security.py (#7771)
  • Issue 3082 - Add test389.topologies compatibility shim for backports (#7725)
  • Issue 7595 - Skip redundant CI runs to relieve the Actions queue (#7749)
  • Issue 7760 - CI - harden dsconf_task_test.py
  • Issue 4701 - Fix UAF when excluding attrs from retro changelog (#7730)
  • Issue 7723 - Range search returns an empty result when its start key is removed (#7724)
  • Issue 7639 - Move log compression outside of global write lock
  • Issue 7631 - Don't install bpftrace by default (#7726)
  • Issue 7735 - Heap overflow when parsing objectclass superior (#7736)
  • Issue 7733 - Typo about nsuniqueid in tombstone_to_conflict (#7734)
  • Issue 7707 - lib389: set nsDS5ReplicaBindDNGroup before ensure_agreement() in join_supplier/hub/consumer (#7708)

Список пакетов

openSUSE Leap 16.0
389-ds-3.0.7~git2.2846d5288-160000.1.1
389-ds-devel-3.0.7~git2.2846d5288-160000.1.1
389-ds-snmp-3.0.7~git2.2846d5288-160000.1.1
lib389-3.0.7~git2.2846d5288-160000.1.1
libsvrcore0-3.0.7~git2.2846d5288-160000.1.1

Описание

A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated replication plugin privileges and returns a boolean match result, the attacker can extract sensitive server configuration metadata, including replication bind DNs and password storage scheme information.


Затронутые продукты
openSUSE Leap 16.0:389-ds-3.0.7~git2.2846d5288-160000.1.1
openSUSE Leap 16.0:389-ds-devel-3.0.7~git2.2846d5288-160000.1.1
openSUSE Leap 16.0:389-ds-snmp-3.0.7~git2.2846d5288-160000.1.1
openSUSE Leap 16.0:lib389-3.0.7~git2.2846d5288-160000.1.1

Ссылки

Описание

A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), the wrapped-record length read from the wire is validated only against an upper bound. A small wire length (0, 1, or 2) produces an encrypted_buffer_count below the already-consumed encrypted_buffer_offset, causing an unsigned subtraction underflow in sasl_io_read_packet(). PR_Recv is then requested to read approximately 4 GiB into a 1024-byte heap buffer, resulting in a heap buffer overflow with attacker-controlled content. After a successful SASL bind with integrity protection (SSF > 0), a remote authenticated attacker can cause a denial of service or potentially achieve remote code execution. This flaw is distinct from CVE-2026-11774, whose fix only guards against upper-bound overflow.


Затронутые продукты
openSUSE Leap 16.0:389-ds-3.0.7~git2.2846d5288-160000.1.1
openSUSE Leap 16.0:389-ds-devel-3.0.7~git2.2846d5288-160000.1.1
openSUSE Leap 16.0:389-ds-snmp-3.0.7~git2.2846d5288-160000.1.1
openSUSE Leap 16.0:lib389-3.0.7~git2.2846d5288-160000.1.1

Ссылки

Описание

A flaw was found in 389 Directory Server. A missing NULL pointer check in the paged results handling of op_shared_search allows an unauthenticated remote attacker to crash the LDAP server by sending a crafted sequence of search requests using the USE_ONE_BACKEND control, resulting in denial of service.


Затронутые продукты
openSUSE Leap 16.0:389-ds-3.0.7~git2.2846d5288-160000.1.1
openSUSE Leap 16.0:389-ds-devel-3.0.7~git2.2846d5288-160000.1.1
openSUSE Leap 16.0:389-ds-snmp-3.0.7~git2.2846d5288-160000.1.1
openSUSE Leap 16.0:lib389-3.0.7~git2.2846d5288-160000.1.1

Ссылки

Описание

A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent, unrelated successful bind, regardless of which SASL mechanism completes that second bind. An attacker can send a SASL PLAIN bind as cn=Directory Manager with an incorrect password, then complete a SASL ANONYMOUS bind on the same connection, causing the server to grant Directory Manager authority without any valid credentials. A variant using a valid low-privileged account's own successful bind instead of an anonymous one is also possible.


Затронутые продукты
openSUSE Leap 16.0:389-ds-3.0.7~git2.2846d5288-160000.1.1
openSUSE Leap 16.0:389-ds-devel-3.0.7~git2.2846d5288-160000.1.1
openSUSE Leap 16.0:389-ds-snmp-3.0.7~git2.2846d5288-160000.1.1
openSUSE Leap 16.0:lib389-3.0.7~git2.2846d5288-160000.1.1

Ссылки

Описание

A flaw was found in 389-ds-base. The Cockpit 389 Console's LDAP editor constructs an ldapsearch command by embedding an LDAP entry's distinguished name (DN) into a shell command string without proper escaping. An LDAP user with delegated privileges to create or rename directory entries could craft a malicious DN containing shell metacharacters. When a Cockpit administrator subsequently views the entry in the 389 Console, the embedded shell command executes with root privileges on the directory server host.


Затронутые продукты
openSUSE Leap 16.0:389-ds-3.0.7~git2.2846d5288-160000.1.1
openSUSE Leap 16.0:389-ds-devel-3.0.7~git2.2846d5288-160000.1.1
openSUSE Leap 16.0:389-ds-snmp-3.0.7~git2.2846d5288-160000.1.1
openSUSE Leap 16.0:lib389-3.0.7~git2.2846d5288-160000.1.1

Ссылки

Описание

A flaw was found in 389 Directory Server. The SELFDN ACI bind-rule evaluator incorrectly matches an anonymous LDAP client's empty bind DN against an empty stored attribute value, allowing an unauthenticated client to satisfy access control checks intended to require a matching authenticated identity. This can allow an anonymous LDAP client to perform an operation, such as adding or modifying a directory entry, that a SELFDN-based ACI intended to restrict to a specific authenticated user.


Затронутые продукты
openSUSE Leap 16.0:389-ds-3.0.7~git2.2846d5288-160000.1.1
openSUSE Leap 16.0:389-ds-devel-3.0.7~git2.2846d5288-160000.1.1
openSUSE Leap 16.0:389-ds-snmp-3.0.7~git2.2846d5288-160000.1.1
openSUSE Leap 16.0:lib389-3.0.7~git2.2846d5288-160000.1.1

Ссылки
Уязвимость openSUSE-SU-2026:21950-1