ELSA-2026-55530

ELSA-2026-55530 - 389-ds:1.4 security update

Type:SECURITY
Impact:IMPORTANT
Release Date:2026-08-17

Description


[1.4.3.39-26]
- Bump version to 1.4.3.39-26
- Resolves: RHEL-183073 - EMBARGOED CVE-2026-11770 389-ds-base: 389-ds-base: pre-auth LDAP filter injection in CleanAllRUV status check [rhel-8.10.z]
- Resolves: RHEL-190782 - CVE-2026-11788 389-ds-base: 389-ds-base: NULL pointer dereference in deref control plugin BER parser [rhel-8.10.z]
- Resolves: RHEL-210880 - EMBARGOED CVE-2026-15722 389-ds:1.4/389-ds-base: 389-ds-base: pre-authentication stack buffer overflow in get_ruvelement_from_berval() via unbounded replica ID parsing [rhel-8.10.z]

[1.4.3.39-25]
- Bump version to 1.4.3.39-25
- Resolves: RHEL-182162 - EMBARGOED CVE-2026-11610 389-ds-base: 389-ds-base: Heap buffer overflow in sasl_io_recv() via padded SASL UNBIND [rhel-8.10.z]
- Resolves: RHEL-183102 - CVE-2026-11774 389-ds-base: 389-ds-base: integer overflow in SASL packet length bypasses size limit

[1.4.3.39-24]
- Bump version to 1.4.3.39-24
- Resolves: RHEL-170278 - Memory leaks in syncrepl plugin during persistent search operations [rhel-8.10.z]
- Resolves: RHEL-163375 - WARN - keys2idl - received NULL idl from index_read_ext_allids
- Resolves: RHEL-159306 - ns-slapd crash in libdb possible memory corruption [rhel-8.10.z]
- Resolves: RHEL-170284 - access log - suspicious wtime optime negative and large values in internal op [rhel-8.10.z]
- Resolves: RHEL-170507 - ns-slapd fails to shutdown when deferred memberof update is in progress [rhel-8.10.z]
- Resolves: RHEL-170509 - Crash in trim_changelog() during the Retro Changelog trimming [rhel-8.10.z]
- Resolves: RHEL-170514 - Possible memory leak when using the Retro Changelog plugin [rhel-8.10.z]
- Resolves: RHEL-170512 - Crash in replica_config_add when manually configuring a replica with an incorrect nsds5ReplicaRoot [rhel-8.10.z]
- Resolves: RHEL-174523 - [RFE] Add OS-level thread names to all server threads [rhel-8.10.z]
- Resolves: RHEL-170483 - test_vlv_recreation_reindex fails on LMDB [rhel-8.10.z]
- Resolves: RHEL-178076 - CVE-2026-9064 389-ds:1.4/389-ds-base: unbounded LDAP controls count in get_ldapmessage_controls_ext() causes CPU and heap amplification (remote DoS) [rhel-8.10.z]

[1.4.3.39-23]
- Resolves: RHEL-137074 - CVE-2025-14905 389-ds:1.4/389-ds-base: 389-ds-base: Remote Code Execution and Denial of Service via heap buffer overflow [rhel-8.10.z]
- Resolves: RHEL-152098 - Scalability issue of replication online initialization with large database [rhel-8.10.z]

[1.4.3.39-22]
- Resolves: RHEL-148485 - Upgrading IDM to latest version: 389-ds-base and ipa-server breaks replication [rhel-8.10.z]

[1.4.3.39-21]
- Resolves: RHEL-141419 - (&(cn:dn:=groups)) no longer returns results [rhel-8.10.z]
- Resolves: RHEL-140272 - ipa-healthcheck is complaining about missing or
incorrectly configured system indexes. [rhel-8.10.z]

[1.4.3.39-20]
- Resolves: RHEL-140086 - Upgrading IDM to latest version: 389-ds-base and ipa-server breaks replication [rhel-8.10.z]

[1.4.3.39-19]
- Resolves: RHEL-117759 - Replication online reinitialization of a large database gets stalled. [rhel-8.10.z]

[1.4.3.39-18]
- Reverts: RHEL-123241 - Attribute uniqueness is not enforced upon modrdn operation [rhel-8.10.z]

[1.4.3.39-17]
- Resolves: RHEL-80491 - Can't rename users member of automember rule [rhel-8.10.z]
- Resolves: RHEL-87191 - Some replication status data are reset upon a restart. [rhel-8.10.z]
- Resolves: RHEL-89785 - Extend log of operations statistics in access log
- Resolves: RHEL-111226 - Error showing local password policy on web UI [rhel-8.10.z]
- Resolves: RHEL-113976 - AddressSanitizer: memory leak in memberof_add_memberof_attr [rhel-8.10.z]
- Resolves: RHEL-117457 - subtree search statistics for index lookup does not report ancestorid/entryrdn lookups
- Resolves: RHEL-117752 - Crash if repl keep alive entry can not be created [rhel-8.10.z]
- Resolves: RHEL-117759 - Replication online reinitialization of a large database gets stalled. [rhel-8.10.z]
- Resolves: RHEL-117765 - Statistics about index lookup report a wrong duration [rhel-8.10.z]
- Resolves: RHEL-123228 - Improve the way to detect asynchronous operations in the access logs [rhel-8.10.z]
- Resolves: RHEL-123241 - Attribute uniqueness is not enforced upon modrdn operation [rhel-8.10.z]
- Resolves: RHEL-123254 - Typo in errors log after a Memberof fixup task. [rhel-8.10.z]
- Resolves: RHEL-123269 - LDAP high CPU usage while handling indexes with IDL scan limit at INT_MAX [rhel-8.10.z]
- Resolves: RHEL-123276 - The new ipahealthcheck test ipahealthcheck.ds.backends.BackendsCheck raises CRITICAL issue [rhel-8.10.z]
- Resolves: RHEL-123363 - When deferred memberof update is enabled after the server crashed it should not launch memberof fixup task by default [rhel-8.10.z]
- Resolves: RHEL-123365 - IPA health check up script shows time skew is over 24 hours [rhel-8.10.z]
- Resolves: RHEL-123920 - Changelog trimming - add number of scanned entries to the log [rhel-8.10.z]
- Resolves: RHEL-126512 - Created user password hash available to see in audit log [rhel-8.10.z]
- Resolves: RHEL-129578 - Fix paged result search locking [rhel-8.10.z]
- Resolves: RHEL-130900 - On RHDS 12.6 The user password policy for a user was created, but the pwdpolicysubentry attribute for this user incorrectly points to the People OU password policy instead of the specific user policy. [rhel-8.10.z]


Related CVEs


CVE-2026-11770
CVE-2026-11788
CVE-2026-15722

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 8 (aarch64) 389-ds-base-1.4.3.39-26.module+el8.10.0+90990+5ec542c6.src.rpmd9384e8e593a009751cfbed466eecd39a54675ac48794675c98fab509c87d013-ol8_aarch64_appstream
389-ds-base-1.4.3.39-26.module+el8.10.0+90990+5ec542c6.aarch64.rpm567b5afe366946d470138de69a5be0f257c17b79b47d8fa41299a3bf53ac0694-ol8_aarch64_appstream
389-ds-base-devel-1.4.3.39-26.module+el8.10.0+90990+5ec542c6.aarch64.rpm8889f99f7e7a50150849e032a92b65356c088103400794418c5c2358a9c83180-ol8_aarch64_appstream
389-ds-base-legacy-tools-1.4.3.39-26.module+el8.10.0+90990+5ec542c6.aarch64.rpm8630d93f525c35f6900cd7529cde9b7a8a4dda3f0b180baa610b3aae1e803fc5-ol8_aarch64_appstream
389-ds-base-libs-1.4.3.39-26.module+el8.10.0+90990+5ec542c6.aarch64.rpm9971a30d98586acadae3b1b357c0b02f046b436a08cdb762a49a3ab220ea80e5-ol8_aarch64_appstream
389-ds-base-snmp-1.4.3.39-26.module+el8.10.0+90990+5ec542c6.aarch64.rpm0eba39763e0179f7a88735a8d8f3d9c12daeb617a346aa951f48a9a5cae7aa41-ol8_aarch64_appstream
python3-lib389-1.4.3.39-26.module+el8.10.0+90990+5ec542c6.noarch.rpm1a5ad89ff4cb97ff75f093b35df6555560b4df92fa5be0838f04508c650c90a8-ol8_aarch64_appstream
Oracle Linux 8 (x86_64) 389-ds-base-1.4.3.39-26.module+el8.10.0+90990+5ec542c6.src.rpmd9384e8e593a009751cfbed466eecd39a54675ac48794675c98fab509c87d013-ol8_x86_64_appstream
389-ds-base-1.4.3.39-26.module+el8.10.0+90990+5ec542c6.x86_64.rpmb9df777bf6531f079e37d230624891d3adc285039381977b8fc2bb10b29ae1f4-ol8_x86_64_appstream
389-ds-base-devel-1.4.3.39-26.module+el8.10.0+90990+5ec542c6.x86_64.rpmbf0b6a80d3999a514e9a75d2c4a4b8233784430b507c67b5bc470f43456dd8d6-ol8_x86_64_appstream
389-ds-base-legacy-tools-1.4.3.39-26.module+el8.10.0+90990+5ec542c6.x86_64.rpm8c4ce0c9e1331179e3a6d443d6af0635613c621ab6dc2101322dd311b93519e2-ol8_x86_64_appstream
389-ds-base-libs-1.4.3.39-26.module+el8.10.0+90990+5ec542c6.x86_64.rpmdefe91b3e6abe38b8c4bf66381e992b6f00650ccac88a00316c7eb861bd9226d-ol8_x86_64_appstream
389-ds-base-snmp-1.4.3.39-26.module+el8.10.0+90990+5ec542c6.x86_64.rpm1d44a76bec23bf945658aec61089abf81793b8a8a912150c16aa630e6918db23-ol8_x86_64_appstream
python3-lib389-1.4.3.39-26.module+el8.10.0+90990+5ec542c6.noarch.rpm1a5ad89ff4cb97ff75f093b35df6555560b4df92fa5be0838f04508c650c90a8-ol8_x86_64_appstream



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete