openSUSE-SU-2026:21950-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21950-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/openSUSE-SU-2026:21950-1
Upstream
CVE (6)
  • CVE-2026-11770
  • CVE-2026-18355
  • CVE-2026-18453
  • CVE-2026-18922
  • CVE-2026-19843
  • CVE-2026-76560
Related
Published
2026-09-24T09:28:31Z
Modified
2026-09-25T18:23:55Z
Summary
Security update for 389-ds
Details

This update for 389-ds fixes the following issues:

  • CVE-2026-11770: pre-auth LDAP filter injection in CleanAllRUV status check (bsc#1273133).
  • CVE-2026-18355: heap buffer overflow in the SASL I/O layer allows a remote authenticated attacker to cause a denial of service or potentially achieve remote code execution (bsc#1279864).
  • CVE-2026-18453: 389-ds-base: 389-ds-base: pre-authentication NULL pointer dereference via paged results and USE_ONE_BACKEND control in op_shared_search (bsc#1279572).
  • CVE-2026-18922: stale identity carried in a Cyrus SASL auxiliary property during SASL PLAIN authentication allows unauthenticated attackers to achieve privilege escalation to Directory Manager (bsc#1279865).
  • CVE-2026-19843: unescaped LDAP DN in Cockpit 389 Console LDAP editor allows an LDAP user with delegated privileges to execute shell commands with root privileges on the directory server host (bsc#1279866).
  • CVE-2026-76560: incorrect matching in the SELFDN ACI bind-rule evaluator allows an anonymous LDAP client to bypass access controls on directory entries containing empty SELFDN attributes (bsc#1279867).

Changes for 389-ds:

  • Update to version 3.0.7~git2.2846d5288:
  • Issue 7757 - stack-buffer-overflow caused by slapi_attr_init_syntax() (#7759)
  • Issue 7796 - A large received replicaID can overflow the storage buffer (#7797)
  • Issue 7041 - Add WebUI test for group member management (#7111)
  • Issue 7808 - CI - harden online_import_nosync_test (#7809)
  • Issue 7611 - PBKDF2 password verification should reject invalid iteration counts (#7632) (#7812)
  • [Backport 389-ds-base-3.0] Update rust-dependencies (#7799)
  • Issue 7595 - Remove the nightly dedup gate and fix dispatched test runs
  • Fix expiration time check (#7718)
  • Issue 7774 - Add backport action (#7775)
  • Issue 7770 - Testimony failure in test_cleanruv_extop_security.py (#7771)
  • Issue 3082 - Add test389.topologies compatibility shim for backports (#7725)
  • Issue 7595 - Skip redundant CI runs to relieve the Actions queue (#7749)
  • Issue 7760 - CI - harden dsconf_task_test.py
  • Issue 4701 - Fix UAF when excluding attrs from retro changelog (#7730)
  • Issue 7723 - Range search returns an empty result when its start key is removed (#7724)
  • Issue 7639 - Move log compression outside of global write lock
  • Issue 7631 - Don't install bpftrace by default (#7726)
  • Issue 7735 - Heap overflow when parsing objectclass superior (#7736)
  • Issue 7733 - Typo about nsuniqueid in tombstone_to_conflict (#7734)
  • Issue 7707 - lib389: set nsDS5ReplicaBindDNGroup before ensure_agreement() in join_supplier/hub/consumer (#7708)
References

Affected packages

openSUSE:Leap 16.0 / 389-ds

Package

Name
389-ds
Purl
pkg:rpm/opensuse/389-ds&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.0.7~git2.2846d5288-160000.1.1

Ecosystem specific

{
    "binaries": [
        {
            "389-ds": "3.0.7~git2.2846d5288-160000.1.1",
            "389-ds-devel": "3.0.7~git2.2846d5288-160000.1.1",
            "389-ds-snmp": "3.0.7~git2.2846d5288-160000.1.1",
            "lib389": "3.0.7~git2.2846d5288-160000.1.1",
            "libsvrcore0": "3.0.7~git2.2846d5288-160000.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21950-1.json"