SUSE-SU-2026:4380-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20264380-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4380-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:4380-1
Upstream
CVE (6)
  • CVE-2026-11770
  • CVE-2026-18355
  • CVE-2026-18453
  • CVE-2026-18922
  • CVE-2026-19843
  • CVE-2026-76560
Related
Published
2026-09-28T15:18:15Z
Modified
2026-09-29T09:15:11Z
Summary
Security update for 389-ds
Details

This update for 389-ds fixes the following issues:

  • CVE-2026-11770: pre-auth LDAP filter injection in CleanAllRUV status check (bsc#1273133).
  • CVE-2026-18355: heap buffer overflow in the SASL I/O layer allows a remote authenticated attacker to cause a denial of service or potentially achieve remote code execution (bsc#1279864).
  • CVE-2026-18453: 389-ds-base: 389-ds-base: pre-authentication NULL pointer dereference via paged results and USE_ONE_BACKEND control in op_shared_search (bsc#1279572).
  • CVE-2026-18922: stale identity carried in a Cyrus SASL auxiliary property during SASL PLAIN authentication allows unauthenticated attackers to achieve privilege escalation to Directory Manager (bsc#1279865).
  • CVE-2026-19843: unescaped LDAP DN in Cockpit 389 Console LDAP editor allows an LDAP user with delegated privileges to execute shell commands with root privileges on the directory server host (bsc#1279866).
  • CVE-2026-76560: incorrect matching in the SELFDN ACI bind-rule evaluator allows an anonymous LDAP client to bypass access controls on directory entries containing empty SELFDN attributes (bsc#1279867).

Changes for 389-ds:

  • Update to version 2.8 LTS (jsc#PED-16949).

  • Update to version 2.8.2~git10.030ada7a6:

  • Issue 6596 - BUG - Compilation Regresion (#6597) (#7866)
  • Issue 7627 - When it exists configured matching rule for an (#7628)
  • [Backport 389-ds-base-2.8] Issue 7611 - PBKDF2 password verification should reject invalid iteration counts (#7852)
  • iadvisories/GHSA-rgxx-hcc4-x3h4 / heap-buffer-overflow in rdn_av_swap (#7826)
  • Migrate pwdchan to base64 0.23 Engine API
  • Update rust-dependencies
  • Issue 7823 - CI: stabilize test_controltype_expired_grace_limit (#7824)
  • Issue 7815 - Support nsslapd-attribute-name-exceptions when adding entries
  • Issue 7757 - stack-buffer-overflow caused by slapi_attr_init_syntax() (#7759)
  • Issue 7796 - A large received replicaID can overflow the storage buffer (#7797)
  • Issue 7041 - Add WebUI test for group member management (#7111)
  • Issue 7808 - CI - harden online_import_nosync_test (#7809)
  • Issue 7595 - Remove the nightly dedup gate and fix dispatched test runs
  • Fix expiration time check (#7718)
  • Issue 7774 - Add backport action (#7775)
  • Issue 7770 - Testimony failure in test_cleanruv_extop_security.py (#7771)
  • Issue 3082 - Add test389.topologies compatibility shim for backports (#7725)
  • Issue 7595 - Skip redundant CI runs to relieve the Actions queue (#7751)
  • Issue 7760 - CI - harden dsconf_task_test.py
  • Issue 4701 - Fix UAF when excluding attrs from retro changelog (#7730)
  • Issue 7723 - Range search returns an empty result when its start key is removed (#7724)
  • Issue 7735 - Heap overflow when parsing objectclass superior (#7736)
  • Issue 7733 - Typo about nsuniqueid in tombstone_to_conflict (#7734)
  • Issue 7284 - Creating local password policy succeeds with incorrect passwordInHistory value (#7662)
  • Issue 7284 - Automated test for creating local password policy with incorrect passwordInHistory value (#7608)
  • Issue 7284 - CI - Fix test_grace_limit_section after pwpolicy validation fix (#7357)
  • Issue 7284 - Creating local password policy succeeds with incorrect passwordInHistory value (#7285)
  • Issue 7707 - lib389: set nsDS5ReplicaBindDNGroup before ensure_agreement() in join_supplier/hub/consumer (#7708)
  • Issue 7711 - Fix typo in accountpolicy --login-history-size help text (#7713)
  • Issue 7688 - BUG - partial address leak in sso token (#7689)
  • Issue 7705 - With memberOfEntryScope set, deferred memberOf skips MODIFY operations (#7706)
  • Issue 7698 - Fix silent entry loss in LMDB bulk import waiter handling (#7699)
  • Issue 7666 - Replication performance degradation during total init on high-latency storage (#7667)
  • Issue 7201 - Syscall overhead in LMDB import writer thread (#7204)
  • Issue 7645 - Add runtime LeakSanitizer leak check (#7646)
  • Issue 7714 - UI - sass import rules are deprecated
  • Issue 7658 - Heap Buffer Overflow in sasl_io_recv() via Padded SASL UNBIND
  • Issue 7710 - MemberOf deferred update - Use condvar instead of sleep loop
  • Issue 7637 - fix cherry-pick error
  • Issue 7637 - UI - Using Arrow Keys in New Object Wizard Resulted in DOM Reload
  • Issue 7578 - schema - attribute refcount is not maintained properly
  • Issue 7605 - Harden CI test ports against ephemeral allocation (#7692)
  • Issue 7528 - Retry the CI image pull instead of failing the job (#7691)
  • Issue 7460 - MOD_REPLACE on groups/link attributes modifies overlap targets (#7461)
  • Issue 7670 - BDB range searches intermittently fail with err=1 under write load (#7671)
  • Issue 7108 - Fix shutdown crash in entry cache destruction (#7163)
  • Issue 7200 - repl-agmt create doesn't set some parameters (#7663)
  • Issue 7611 - Preserve legacy PBKDF2 hash compatibility (#7649)
  • Issue 7547 - Heap buffer overflow in ldap_utf8prev()
  • Issue 7611 - PBKDF2 password verification should reject invalid iteration count (#7613)
  • Issue 7558 - Total init sends the suffix entry twice (#7640)
  • Issue 7635 - Integer Underflow in {SMD5} Password Comparison (#7636)
  • Issue 7406 - Fix ldap-agent SNMP stats file loading (#7630)
  • Issue 7621 - Stack Buffer Overflow in Password checkPrefix
  • Issue 7623 - Heap Buffer Overflow in 389-ds-base Audit Log Password Masking
  • Issue 7602 - CI - lib389 user compare fails due to parentid mismatch (#7603)
  • Issue 7537 - CI - Fix replication log monitoring parser/timing failures (#7592)
  • Issue 7593 - Fix testimony docstring for SASL overflow test (#7606)
  • Issue 7530 - CI - Stabilize DNA plugin replication tests timing out in CI (#7572)
  • Issue 7593 - Reject invalid SASL packet length values in sasl_io_start_packet (#7594)
  • Issue 3555 - UI - Fix audit issue with npm - ws, js-yaml, js-yaml, postcss, uuid
  • Issue 7541 - Add invalid ACL text header regression test (#7591)
  • Issue 7541 - heap-buffer-overflows in __aclp__normalize_acltxt() (#7542)
  • Issue 7576 - Fix leak of temporary attribute syntax hash tables after schema reload
  • Issue 7198 - Web console doesn't show sub-suffix when parent-suffix points to an entry (#7202)
  • Issue 7558 - During online import, the IDL should be created with in-depth first approach (#7559)
  • Issue 7500 - Prevent unsigned integer underflow during stalled import
  • Issue 7560 - lib389 - Add helper function for checking ASAN files
  • Issue 7539 - Server shutdown during online reindex may lead to data loss (#7540)
  • Issue 7549 - Substring index should validate minimum nsSubStrBegin/nsSubStrEnd values (#7550)
  • Issue 7440 - Substring index produces empty results and can crash when non-default nsSubStrBegin/nsSubStrEnd lengths are configured (#7441)
  • Issue 7267 - MDB_BAD_VALSIZE error when updating index (#7268)
  • Issue 7327 - dsctl healthcheck DSMOLE0001 inaccurate recommendations with multiple backends (#7328)
  • Issue 7372 - Reindex adds tombstones to ancestorid causing export failures (#7373)
  • Issue 7437 - LeakSanitizer: memory leaks in CoS cache error paths (#7438)
  • Issue 6922 - AddressSanitizer: leaks found by acl test suite
  • Issue 3555 - UI - Fix audit issue with npm - brace-expansion (#7556)
  • Issue 7554 - deref plugin null pointer dereference if ber_init fails
  • Issue 7519 - Ignore obsolete entrydn index when entryrdn is enabled (#7526)
  • Issue 7514 - Crash when doing moddn on very large subtree
  • Issue 7516 - dblayer_bulk_nextdata should not return an error when maxrecords is hit
  • Issue 7300 - RFE - Add OS-level thread names to all server threads (#7301)
  • Issue 7307 - RFE - Expose work queue and worker utilization metrics (#7308)
  • Issue 7464 - CLI - allow dsidm to work with other user types
  • Issue 7457 - Refactor memberOf perf test (#7458)
  • Issue 7452 - UI - password polices - reorganize settings
  • Issue 7431 - password policy - passwordBadWords is ignored in local policies
  • Issue 7155 - build_candidate_list - Database error 11 with range search (#7156)
  • Issue 7417 - UI - global password policy syntax settings missing passwordMaxRepeats
  • Issue 3555 - UI - Fix audit issue with npm - brace-expansion (#7411)
  • Issue 7088 - Change log level for 'Can't locate CSN' error message
  • Issue 7423 - cleanup pblock after freeing pre/post entries
  • Issue 7418 - Use-after-free in deferred memberof (#7419)
  • Issue 7407 - dbscan -k option display entries that do not match the specified key
  • Issue 7394 - UI - Manual typing of ports can leave out digits (#7395)
  • Issue 7277 - UI - Fix Japanese translation errors errors in Cockpit UI (#7386)
  • Issue 7126 - WARN - keys2idl - received NULL idl from index_read_ext_allids (#7127)
  • Issue 7246 - correct formatting of 'Gen as CSN' in dsctl get-nsstate output (#7247)
  • Issue 7370 - Runtime LSan/TSan injection for pytest (#7371)
  • Issue 7378 - Make sure suffix entry always gets assigned ID 1
  • Issue 7380 - Internal op with negative wtime and large optime (#7381)
  • Issue 7362 - UI - Some FormSelect onChange parameters are reversed
  • Issue 7368 - UI - global password policy page is missing passwordmintokenlength
  • Issue 7366 - Memory leaks in syncrepl plugin during persistent search operations (#7367)
  • Issue 7271 - Add test for retrocl trimming shutdown crash (#7356)
  • Issue 3555 - UI - Fix audit issue with npm - flatted, picomatch (#7364)
  • Issue 7277 - UI - Fix Japanese translation for 'Successfully updated group' in Cockpit UI (#7278)
  • Issue 7275 - UI - Improve password policy field validation in Cockpit UI (#7276)
  • Issue 7279 - UI - Fix typo in export certificate dialog (#7280)
  • Issue 6758 - Fix Enable Replication dropdown not opening (#7262)
  • Issue 6758 - Use OUIA selectors for WebUI plugin tests (#7182)
  • Issue 6758 - Fix WebUI monitoring test failure due to FormSelect component deprecation (#7004)
  • Issue 6758 - Fix failing webUI tests
  • Issue 1704 - DNA plugin creates invalid shared config entry with port 0 (#7352)
  • Issue 6753 - Removing ticket 477828 test and porting to DSLdapObject (#6989)
  • Issue 7346 - DS does not handle escape char in bind user (#7347)
  • Issue 7322 - Fix cherry-pick error (reject repl agmt that points to itself)
  • Issue 7322 - Reject adding a replication agreement that points to itself
  • Issue 7342 - CI - repl config regression (#7343)
  • Issue 7291 - Crash when configuring a replica with an incorrect nsds5ReplicaRoot (#7292)
  • Issue - UI - Improve suffix import LDIF table
  • Issue 7325 - UI - new error parser missing import
  • Issue 7325 - UI - create an error parser for cockpit spawn errors
  • Issue 7319 - Action menu for certificates remains in empty certificate list (#7320)
  • Issue 7265 - CI - fix retro changelog maxage validation test
  • Issue 7093 - A password policy can be created even when an identical policy already exists (#7283)
  • Issue 7233 - test_produce_division_by_zero fails with IsADirectoryError in conftest.py (#7234)
  • Issue 7271 - Add new plugin pre-close function check to plugin_invoke_plugin_pb
  • Issue 7304 - retrocl should not cache DN
  • Issue 7265 - Add dse modify callback to validate retrocl trimming settings
  • Issue 7152 - ns-slapd fails to shutdown when deferred memberof update is in progress (#7187)
  • Issue 3555 - UI - Fix audit issue with npm - ajv, minimatch (#7298)
  • Issue 7271 - implement a pre-close plugin function
  • Issue 7295 - changelog max age validation cherry-pick error
  • Issue 7265 - changelog maxage validation is not strict enough
  • Issue 7273 - In a chaining environment binding as remote user causes an invalid error in the logs
  • Issue 7271 - plugins that create threads need to update active thread count
  • Issue 5853 - Update concread to 0.5.10
  • Issue 7053 - Remove memberof_del_dn_from_groups from MemberOf plugin (#7064)
  • Issue 7223 - Remove integerOrderingMatch requirement for parentid (#7264)
  • Issue 7243 - UI - fix certificate table and modal
  • Issue 7066/7052 - allow password history to be set to zero and remove history
  • Issue 7223 - Use lexicographical order for ancestorid (#7256)
  • Issue 7213 - (2nd) MDB_BAD_VALSIZE error while handling VLV (#7258)
  • Issue 7184 - (2nd) argparse.HelpFormatter _format_actions_usage() is deprecated (#7257)
  • Issue - CLI - dsctl db2index needs some hardening with MBD
  • Issue 7248 - CLI - attribute uniqueness - fix usage for exclude subtree option
  • Issue 7231 - Sync repl tests fail in FIPS mode due to non FIPS compliant crypto (#7232)
  • Issue 7224 - CI Test - Simplify test_reserve_descriptor_validation (#7225)
  • Issue 7150 - Compressed access log rotations skipped, accesslog-list out of sync (#7151)
  • Issue 7121 - (2nd) LeakSanitizer: various leaks during replication (#7212)
  • Issue 6947 - Fix health_system_indexes_test.py
  • Issue 7076 - Fix revert_cache() never called in modrdn (#7220)
  • Issue 7076, 6992, 6784, 6214 - Fix CI test failures (#7077)
  • Issue 7096 - (2nd) During replication online total init the function idl_id_is_in_idlist is not scaling with large database (#7205)
  • Issue 7223 - Add dsctl index-check command for offline index repair
  • Issue 7223 - Detect and log index ordering mismatch during backend startup
  • Issue 7223 - Add upgrade function to remove ancestorid index config entry
  • Issue 7223 - Add upgrade function to remove nsIndexIDListScanLimit from parentid
  • Issue 7223 - Revert index scan limits for system indexes
  • Issue 6476 - Fix build failure with GCC 15
  • Issue 6542 - RPM build errors on Fedora 42
  • Issue 7213 - MDB_BAD_VALSIZE error while handling VLV (#7214)
  • Issue 7027 - (2nd) 389-ds-base OpenScanHub Leaks Detected (#7211)
  • Issue 7184 - argparse.HelpFormatter _format_actions_usage() is deprecated
  • Issue 7189 - DSBLE0007 generates incorrect remediation commands for scan limits
  • Issue 7172 - (2nd) Index ordering mismatch after upgrade (#7180)
  • Issue 7172 - Index ordering mismatch after upgrade (#7173)
  • Issue - Revise paged result search locking
  • Issue 7096 - During replication online total init the function idl_id_is_in_idlist is not scaling with large database (#7145)
  • Issue 7049 - RetroCL plugin generates invalid LDIF
References

Affected packages

SUSE:Linux Enterprise Module for Server Applications 15 SP7 / 389-ds

Package

Name
389-ds
Purl
pkg:rpm/suse/389-ds&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.8.2~git10.030ada7a6-150700.3.25.1

Ecosystem specific

{
    "binaries":  [
        {
            "389-ds":  "2.8.2~git10.030ada7a6-150700.3.25.1",
            "389-ds-devel":  "2.8.2~git10.030ada7a6-150700.3.25.1",
            "lib389":  "2.8.2~git10.030ada7a6-150700.3.25.1",
            "libsvrcore0":  "2.8.2~git10.030ada7a6-150700.3.25.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4380-1.json"