389-ds-base is an LDAPv3 compliant server which includes the LDAP server and command line utilities for server administration.
Security Fix(es):
A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing an unauthenticated remote attacker to crash the LDAP server when the system is under memory pressure.(CVE-2026-11788)
A flaw was found in 389 Directory Server in the __aclp__normalize_acltxt() function of aclparse.c. A malformed ACI (Access Control Instruction) string can trigger heap-buffer-overflow writes and reads during ACI parsing. The function fails to validate that the ACI keyword has sufficient length after whitespace stripping, leading to a 1-byte out-of-bounds write and subsequent out-of-bounds reads. An authenticated user with write access to the aci attribute could send a crafted ACI value to silently corrupt heap memory in the directory server process.(CVE-2026-12528)
{
"severity": "High"
}{
"aarch64": [
"389-ds-base-3.1.1-12.oe2403sp1.aarch64.rpm",
"389-ds-base-debuginfo-3.1.1-12.oe2403sp1.aarch64.rpm",
"389-ds-base-debugsource-3.1.1-12.oe2403sp1.aarch64.rpm",
"389-ds-base-devel-3.1.1-12.oe2403sp1.aarch64.rpm",
"389-ds-base-help-3.1.1-12.oe2403sp1.aarch64.rpm",
"389-ds-base-snmp-3.1.1-12.oe2403sp1.aarch64.rpm"
],
"noarch": [
"cockpit-389-ds-3.1.1-12.oe2403sp1.noarch.rpm",
"python3-lib389-3.1.1-12.oe2403sp1.noarch.rpm"
],
"src": [
"389-ds-base-3.1.1-12.oe2403sp1.src.rpm"
],
"x86_64": [
"389-ds-base-3.1.1-12.oe2403sp1.x86_64.rpm",
"389-ds-base-debuginfo-3.1.1-12.oe2403sp1.x86_64.rpm",
"389-ds-base-debugsource-3.1.1-12.oe2403sp1.x86_64.rpm",
"389-ds-base-devel-3.1.1-12.oe2403sp1.x86_64.rpm",
"389-ds-base-help-3.1.1-12.oe2403sp1.x86_64.rpm",
"389-ds-base-snmp-3.1.1-12.oe2403sp1.x86_64.rpm"
]
}