{"id":"SUSE-SU-2026:4380-1","summary":"Security update for 389-ds","details":"This update for 389-ds fixes the following issues:\n\n- CVE-2026-11770: pre-auth LDAP filter injection in CleanAllRUV status check (bsc#1273133).\n- CVE-2026-18355: heap buffer overflow in the SASL I/O layer allows a remote authenticated attacker to cause a denial of\n  service or potentially achieve remote code execution (bsc#1279864).\n- CVE-2026-18453: 389-ds-base: 389-ds-base: pre-authentication NULL pointer dereference via paged results and\n  USE_ONE_BACKEND control in op_shared_search (bsc#1279572).\n- CVE-2026-18922: stale identity carried in a Cyrus SASL auxiliary property during SASL PLAIN authentication allows\n  unauthenticated attackers to achieve privilege escalation to Directory Manager (bsc#1279865).\n- CVE-2026-19843: unescaped LDAP DN in Cockpit 389 Console LDAP editor allows an LDAP user with delegated privileges to\n  execute shell commands with root privileges on the directory server host (bsc#1279866).\n- CVE-2026-76560: incorrect matching in the SELFDN ACI bind-rule evaluator allows an anonymous LDAP client to bypass\n  access controls on directory entries containing empty SELFDN attributes (bsc#1279867).\n\nChanges for 389-ds:\n\n- Update to version 2.8 LTS (jsc#PED-16949).\n  \n- Update to version 2.8.2~git10.030ada7a6:\n * Issue 6596 - BUG - Compilation Regresion (#6597) (#7866)\n * Issue 7627 - When it exists configured matching rule for an (#7628)\n * [Backport 389-ds-base-2.8] Issue 7611 - PBKDF2 password verification should reject invalid iteration counts (#7852)\n * iadvisories/GHSA-rgxx-hcc4-x3h4 / heap-buffer-overflow in rdn_av_swap (#7826)\n * Migrate pwdchan to base64 0.23 Engine API\n * Update rust-dependencies\n * Issue 7823 - CI: stabilize test_controltype_expired_grace_limit (#7824)\n * Issue 7815 - Support nsslapd-attribute-name-exceptions when adding entries\n * Issue 7757 - stack-buffer-overflow caused by slapi_attr_init_syntax() (#7759)\n * Issue 7796 - A large received replicaID can overflow the storage buffer (#7797)\n * Issue 7041 - Add WebUI test for group member management (#7111)\n * Issue 7808 - CI - harden online_import_nosync_test (#7809)\n * Issue 7595 - Remove the nightly dedup gate and fix dispatched test runs\n * Fix expiration time check (#7718)\n * Issue 7774 - Add backport action (#7775)\n * Issue 7770 - Testimony failure in test_cleanruv_extop_security.py (#7771)\n * Issue 3082 - Add test389.topologies compatibility shim for backports (#7725)\n * Issue 7595 - Skip redundant CI runs to relieve the Actions queue (#7751)\n * Issue 7760 - CI - harden dsconf_task_test.py\n * Issue 4701 - Fix UAF when excluding attrs from retro changelog (#7730)\n * Issue 7723 - Range search returns an empty result when its start key is removed (#7724)\n * Issue 7735 - Heap overflow when parsing objectclass superior (#7736)\n * Issue 7733 - Typo about nsuniqueid in tombstone_to_conflict (#7734)\n * Issue 7284 - Creating local password policy succeeds with incorrect passwordInHistory value (#7662)\n * Issue 7284 - Automated test for creating local password policy with incorrect passwordInHistory value (#7608)\n * Issue 7284 - CI - Fix test_grace_limit_section after pwpolicy validation fix (#7357)\n * Issue 7284 - Creating local password policy succeeds with incorrect passwordInHistory value (#7285)\n * Issue 7707 - lib389: set nsDS5ReplicaBindDNGroup before ensure_agreement() in join_supplier/hub/consumer (#7708)\n * Issue 7711 - Fix typo in accountpolicy --login-history-size help text (#7713)\n * Issue 7688 - BUG - partial address leak in sso token (#7689)\n * Issue 7705 - With memberOfEntryScope set, deferred memberOf skips MODIFY operations (#7706)\n * Issue 7698 - Fix silent entry loss in LMDB bulk import waiter handling (#7699)\n * Issue 7666 - Replication performance degradation during total init on high-latency storage (#7667)\n * Issue 7201 - Syscall overhead in LMDB import writer thread (#7204)\n * Issue 7645 - Add runtime LeakSanitizer leak check (#7646)\n * Issue 7714 - UI - sass import rules are deprecated\n * Issue 7658 - Heap Buffer Overflow in sasl_io_recv() via Padded SASL UNBIND\n * Issue 7710 - MemberOf deferred update - Use condvar instead of sleep loop\n * Issue 7637 - fix cherry-pick error\n * Issue 7637 - UI - Using Arrow Keys in New Object Wizard Resulted in DOM Reload\n * Issue 7578 - schema - attribute refcount is not maintained properly\n * Issue 7605 - Harden CI test ports against ephemeral allocation (#7692)\n * Issue 7528 - Retry the CI image pull instead of failing the job (#7691)\n * Issue 7460 - MOD_REPLACE on groups/link attributes modifies overlap targets (#7461)\n * Issue 7670 - BDB range searches intermittently fail with err=1 under write load (#7671)\n * Issue 7108 - Fix shutdown crash in entry cache destruction (#7163)\n * Issue 7200 - repl-agmt create doesn't set some parameters (#7663)\n * Issue 7611 - Preserve legacy PBKDF2 hash compatibility (#7649)\n * Issue 7547 - Heap buffer overflow in ldap_utf8prev()\n * Issue 7611 - PBKDF2 password verification should reject invalid iteration count (#7613)\n * Issue 7558 - Total init sends the suffix entry twice (#7640)\n * Issue 7635 - Integer Underflow in {SMD5} Password Comparison (#7636)\n * Issue 7406 - Fix ldap-agent SNMP stats file loading (#7630)\n * Issue 7621 - Stack Buffer Overflow in Password checkPrefix\n * Issue 7623 - Heap Buffer Overflow in 389-ds-base Audit Log Password Masking\n * Issue 7602 - CI - lib389 user compare fails due to parentid mismatch (#7603)\n * Issue 7537 - CI - Fix replication log monitoring parser/timing failures (#7592)\n * Issue 7593 - Fix testimony docstring for SASL overflow test (#7606)\n * Issue 7530 - CI - Stabilize DNA plugin replication tests timing out in CI (#7572)\n * Issue 7593 - Reject invalid SASL packet length values in sasl_io_start_packet (#7594)\n * Issue 3555 - UI - Fix audit issue with npm - ws, js-yaml, js-yaml, postcss, uuid\n * Issue 7541 - Add invalid ACL text header regression test (#7591)\n * Issue 7541 - heap-buffer-overflows in __aclp__normalize_acltxt() (#7542)\n * Issue 7576 - Fix leak of temporary attribute syntax hash tables after schema reload\n * Issue 7198 - Web console doesn't show sub-suffix when parent-suffix points to an entry (#7202)\n * Issue 7558 - During online import, the IDL should be created with in-depth first approach (#7559)\n * Issue 7500 - Prevent unsigned integer underflow during stalled import\n * Issue 7560 - lib389 - Add helper function for checking ASAN files\n * Issue 7539 - Server shutdown during online reindex may lead to data loss (#7540)\n * Issue 7549 - Substring index should validate minimum nsSubStrBegin/nsSubStrEnd values (#7550)\n * Issue 7440 - Substring index produces empty results and can crash when non-default nsSubStrBegin/nsSubStrEnd lengths are configured (#7441)\n * Issue 7267 - MDB_BAD_VALSIZE error when updating index (#7268)\n * Issue 7327 - dsctl healthcheck DSMOLE0001 inaccurate recommendations with multiple backends (#7328)\n * Issue 7372 - Reindex adds tombstones to ancestorid causing export failures (#7373)\n * Issue 7437 - LeakSanitizer: memory leaks in CoS cache error paths (#7438)\n * Issue 6922 - AddressSanitizer: leaks found by acl test suite\n * Issue 3555 - UI - Fix audit issue with npm - brace-expansion (#7556)\n * Issue 7554 - deref plugin null pointer dereference if ber_init fails\n * Issue 7519 - Ignore obsolete entrydn index when entryrdn is enabled (#7526)\n * Issue 7514 - Crash when doing moddn on very large subtree\n * Issue 7516 - dblayer_bulk_nextdata should not return an error when maxrecords is hit\n * Issue 7300 - RFE - Add OS-level thread names to all server threads (#7301)\n * Issue 7307 - RFE - Expose work queue and worker utilization metrics (#7308)\n * Issue 7464 - CLI - allow dsidm to work with other user types\n * Issue 7457 - Refactor memberOf perf test (#7458)\n * Issue 7452 - UI - password polices - reorganize settings\n * Issue 7431 - password policy - passwordBadWords is ignored in local policies\n * Issue 7155 - build_candidate_list - Database error 11 with range search (#7156)\n * Issue 7417 - UI - global password policy syntax settings missing passwordMaxRepeats\n * Issue 3555 - UI - Fix audit issue with npm - brace-expansion (#7411)\n * Issue 7088 - Change log level for 'Can't locate CSN' error message\n * Issue 7423 - cleanup pblock after freeing pre/post entries\n * Issue 7418 - Use-after-free in deferred memberof (#7419)\n * Issue 7407 - dbscan -k option display entries that do not match the specified key\n * Issue 7394 - UI - Manual typing of ports can leave out digits (#7395)\n * Issue 7277 - UI - Fix Japanese translation errors errors in Cockpit UI (#7386)\n * Issue 7126 - WARN - keys2idl - received NULL idl from index_read_ext_allids (#7127)\n * Issue 7246 - correct formatting of 'Gen as CSN' in dsctl get-nsstate output (#7247)\n * Issue 7370 - Runtime LSan/TSan injection for pytest (#7371)\n * Issue 7378 - Make sure suffix entry always gets assigned ID 1\n * Issue 7380 - Internal op with negative wtime and large optime (#7381)\n * Issue 7362 - UI - Some FormSelect onChange parameters are reversed\n * Issue 7368 - UI - global password policy page is missing passwordmintokenlength\n * Issue 7366 - Memory leaks in syncrepl plugin during persistent search operations (#7367)\n * Issue 7271 - Add test for retrocl trimming shutdown crash (#7356)\n * Issue 3555 - UI - Fix audit issue with npm - flatted, picomatch (#7364)\n * Issue 7277 - UI - Fix Japanese translation for 'Successfully updated group' in Cockpit UI (#7278)\n * Issue 7275 - UI - Improve password policy field validation in Cockpit UI (#7276)\n * Issue 7279 - UI - Fix typo in export certificate dialog (#7280)\n * Issue 6758 - Fix Enable Replication dropdown not opening (#7262)\n * Issue 6758 - Use OUIA selectors for WebUI plugin tests (#7182)\n * Issue 6758 - Fix WebUI monitoring test failure due to FormSelect component deprecation (#7004)\n * Issue 6758 - Fix failing webUI tests\n * Issue 1704 - DNA plugin creates invalid shared config entry with port 0 (#7352)\n * Issue 6753 - Removing ticket 477828 test and porting to DSLdapObject (#6989)\n * Issue 7346 - DS does not handle escape char in bind user (#7347)\n * Issue 7322 - Fix cherry-pick error (reject repl agmt that points to itself)\n * Issue 7322 - Reject adding a replication agreement that points to itself\n * Issue 7342 - CI - repl config regression (#7343)\n * Issue 7291 - Crash when configuring a replica with an incorrect nsds5ReplicaRoot (#7292)\n * Issue - UI - Improve suffix import LDIF table\n * Issue 7325 - UI - new error parser missing import\n * Issue 7325 - UI - create an error parser for cockpit spawn errors\n * Issue 7319 - Action menu for certificates remains in empty certificate list (#7320)\n * Issue 7265 - CI - fix retro changelog maxage validation test\n * Issue 7093 - A password policy can be created even when an identical policy already exists (#7283)\n * Issue 7233 - test_produce_division_by_zero fails with IsADirectoryError in conftest.py (#7234)\n * Issue 7271 - Add new plugin pre-close function check to plugin_invoke_plugin_pb\n * Issue 7304 - retrocl should not cache DN\n * Issue 7265 - Add dse modify callback to validate retrocl trimming settings\n * Issue 7152 - ns-slapd fails to shutdown when deferred memberof update is in progress (#7187)\n * Issue 3555 - UI - Fix audit issue with npm - ajv, minimatch (#7298)\n * Issue 7271 - implement a pre-close plugin function\n * Issue 7295 - changelog max age validation cherry-pick error\n * Issue 7265 - changelog maxage validation is not strict enough\n * Issue 7273 - In a chaining environment binding as remote user causes an invalid error in the logs\n * Issue 7271 - plugins that create threads need to update active thread count\n * Issue 5853 - Update concread to 0.5.10\n * Issue 7053 - Remove memberof_del_dn_from_groups from MemberOf plugin (#7064)\n * Issue 7223 - Remove integerOrderingMatch requirement for parentid (#7264)\n * Issue 7243 - UI - fix certificate table and modal\n * Issue 7066/7052 - allow password history to be set to zero and remove history\n * Issue 7223 - Use lexicographical order for ancestorid (#7256)\n * Issue 7213 - (2nd) MDB_BAD_VALSIZE error while handling VLV (#7258)\n * Issue 7184 - (2nd) argparse.HelpFormatter _format_actions_usage() is deprecated (#7257)\n * Issue - CLI - dsctl db2index needs some hardening with MBD\n * Issue 7248 - CLI - attribute uniqueness - fix usage for exclude subtree option\n * Issue 7231 - Sync repl tests fail in FIPS mode due to non FIPS compliant crypto (#7232)\n * Issue 7224 - CI Test - Simplify test_reserve_descriptor_validation (#7225)\n * Issue 7150 - Compressed access log rotations skipped, accesslog-list out of sync (#7151)\n * Issue 7121 - (2nd) LeakSanitizer: various leaks during replication (#7212)\n * Issue 6947 - Fix health_system_indexes_test.py\n * Issue 7076 - Fix revert_cache() never called in modrdn (#7220)\n * Issue 7076, 6992, 6784, 6214 - Fix CI test failures (#7077)\n * Issue 7096 - (2nd) During replication online total init the function idl_id_is_in_idlist is not scaling with large database (#7205)\n * Issue 7223 - Add dsctl index-check command for offline index repair\n * Issue 7223 - Detect and log index ordering mismatch during backend startup\n * Issue 7223 - Add upgrade function to remove ancestorid index config entry\n * Issue 7223 - Add upgrade function to remove nsIndexIDListScanLimit from parentid\n * Issue 7223 - Revert index scan limits for system indexes\n * Issue 6476 - Fix build failure with GCC 15\n * Issue 6542 - RPM build errors on Fedora 42\n * Issue 7213 - MDB_BAD_VALSIZE error while handling VLV (#7214)\n * Issue 7027 - (2nd) 389-ds-base OpenScanHub Leaks Detected (#7211)\n * Issue 7184 - argparse.HelpFormatter _format_actions_usage() is deprecated\n * Issue 7189 - DSBLE0007 generates incorrect remediation commands for scan limits\n * Issue 7172 - (2nd) Index ordering mismatch after upgrade (#7180)\n * Issue 7172 - Index ordering mismatch after upgrade (#7173)\n * Issue - Revise paged result search locking\n * Issue 7096 - During replication online total init the function idl_id_is_in_idlist is not scaling with large database (#7145)\n * Issue 7049 - RetroCL plugin generates invalid LDIF\n","modified":"2026-09-29T09:15:11.288012752Z","published":"2026-09-28T15:18:15Z","related":["CVE-2026-11770","CVE-2026-18355","CVE-2026-18453","CVE-2026-18922","CVE-2026-19843","CVE-2026-76560"],"upstream":["CVE-2026-11770","CVE-2026-18355","CVE-2026-18453","CVE-2026-18922","CVE-2026-19843","CVE-2026-76560"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20264380-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1273133"},{"type":"REPORT","url":"https://bugzilla.suse.com/1279572"},{"type":"REPORT","url":"https://bugzilla.suse.com/1279864"},{"type":"REPORT","url":"https://bugzilla.suse.com/1279865"},{"type":"REPORT","url":"https://bugzilla.suse.com/1279866"},{"type":"REPORT","url":"https://bugzilla.suse.com/1279867"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11770"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-18355"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-18453"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-18922"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-19843"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-76560"}],"affected":[{"package":{"name":"389-ds","ecosystem":"SUSE:Linux Enterprise Module for Server Applications 15 SP7","purl":"pkg:rpm/suse/389-ds&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.8.2~git10.030ada7a6-150700.3.25.1"}]}],"ecosystem_specific":{"binaries":[{"lib389":"2.8.2~git10.030ada7a6-150700.3.25.1","libsvrcore0":"2.8.2~git10.030ada7a6-150700.3.25.1","389-ds":"2.8.2~git10.030ada7a6-150700.3.25.1","389-ds-devel":"2.8.2~git10.030ada7a6-150700.3.25.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4380-1.json"}}],"schema_version":"1.9.0"}