{"id":"SUSE-SU-2026:23916-1","summary":"Security update for 389-ds","details":"This update for 389-ds fixes the following issues:\n\n- CVE-2026-11770: pre-auth LDAP filter injection in CleanAllRUV status check (bsc#1273133).\n- CVE-2026-18355: heap buffer overflow in the SASL I/O layer allows a remote authenticated attacker to cause a denial of\n  service or potentially achieve remote code execution (bsc#1279864).\n- CVE-2026-18453: 389-ds-base: 389-ds-base: pre-authentication NULL pointer dereference via paged results and\n  USE_ONE_BACKEND control in op_shared_search (bsc#1279572).\n- CVE-2026-18922: stale identity carried in a Cyrus SASL auxiliary property during SASL PLAIN authentication allows\n  unauthenticated attackers to achieve privilege escalation to Directory Manager (bsc#1279865).\n- CVE-2026-19843: unescaped LDAP DN in Cockpit 389 Console LDAP editor allows an LDAP user with delegated privileges to\n  execute shell commands with root privileges on the directory server host (bsc#1279866).\n- CVE-2026-76560: incorrect matching in the SELFDN ACI bind-rule evaluator allows an anonymous LDAP client to bypass\n  access controls on directory entries containing empty SELFDN attributes (bsc#1279867).\n\nChanges for 389-ds:\n\n- Update to version 3.0.7~git2.2846d5288:\n\n * Issue 7757 - stack-buffer-overflow caused by slapi_attr_init_syntax() (#7759)\n * Issue 7796 - A large received replicaID can overflow the storage buffer (#7797)\n * Issue 7041 - Add WebUI test for group member management (#7111)\n * Issue 7808 - CI - harden online_import_nosync_test (#7809)\n * Issue 7611 - PBKDF2 password verification should reject invalid iteration counts (#7632) (#7812)\n * [Backport 389-ds-base-3.0] Update rust-dependencies (#7799)\n * Issue 7595 - Remove the nightly dedup gate and fix dispatched test runs\n * Fix expiration time check (#7718)\n * Issue 7774 - Add backport action (#7775)\n * Issue 7770 - Testimony failure in test_cleanruv_extop_security.py (#7771)\n * Issue 3082 - Add test389.topologies compatibility shim for backports (#7725)\n * Issue 7595 - Skip redundant CI runs to relieve the Actions queue (#7749)\n * Issue 7760 - CI - harden dsconf_task_test.py\n * Issue 4701 - Fix UAF when excluding attrs from retro changelog (#7730)\n * Issue 7723 - Range search returns an empty result when its start key is removed (#7724)\n * Issue 7639 - Move log compression outside of global write lock\n * Issue 7631 - Don't install bpftrace by default (#7726)\n * Issue 7735 - Heap overflow when parsing objectclass superior (#7736)\n * Issue 7733 - Typo about nsuniqueid in tombstone_to_conflict (#7734)\n * Issue 7707 - lib389: set nsDS5ReplicaBindDNGroup before ensure_agreement() in join_supplier/hub/consumer (#7708)\n","modified":"2026-09-30T18:23:13.030691981Z","published":"2026-09-24T09:24:13Z","related":["CVE-2026-11770","CVE-2026-18355","CVE-2026-18453","CVE-2026-18922","CVE-2026-19843","CVE-2026-76560"],"upstream":["CVE-2026-11770","CVE-2026-18355","CVE-2026-18453","CVE-2026-18922","CVE-2026-19843","CVE-2026-76560"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202623916-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1273133"},{"type":"REPORT","url":"https://bugzilla.suse.com/1279572"},{"type":"REPORT","url":"https://bugzilla.suse.com/1279864"},{"type":"REPORT","url":"https://bugzilla.suse.com/1279865"},{"type":"REPORT","url":"https://bugzilla.suse.com/1279866"},{"type":"REPORT","url":"https://bugzilla.suse.com/1279867"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11770"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-18355"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-18453"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-18922"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-19843"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-76560"}],"affected":[{"package":{"name":"389-ds","ecosystem":"SUSE:Linux Enterprise Server 16.0","purl":"pkg:rpm/suse/389-ds&distro=SUSE%20Linux%20Enterprise%20Server%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.0.7~git2.2846d5288-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"389-ds":"3.0.7~git2.2846d5288-160000.1.1","389-ds-devel":"3.0.7~git2.2846d5288-160000.1.1","389-ds-snmp":"3.0.7~git2.2846d5288-160000.1.1","lib389":"3.0.7~git2.2846d5288-160000.1.1","libsvrcore0":"3.0.7~git2.2846d5288-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:23916-1.json"}},{"package":{"name":"389-ds","ecosystem":"SUSE:Linux Enterprise Server for SAP applications 16.0","purl":"pkg:rpm/suse/389-ds&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.0.7~git2.2846d5288-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"libsvrcore0":"3.0.7~git2.2846d5288-160000.1.1","389-ds":"3.0.7~git2.2846d5288-160000.1.1","389-ds-devel":"3.0.7~git2.2846d5288-160000.1.1","389-ds-snmp":"3.0.7~git2.2846d5288-160000.1.1","lib389":"3.0.7~git2.2846d5288-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:23916-1.json"}}],"schema_version":"1.9.0"}