| Type: | SECURITY |
| Impact: | CRITICAL |
| Release Date: | 2026-09-10 |
[1.4.3.39-28]
- Bump version to 1.4.3.39-28
- Resolves: RHEL-222326 - EMBARGOED CVE-2026-18453 389-ds:1.4/389-ds-base: 389-ds-base: pre-authentication NULL pointer dereference via paged results and USE_ONE_BACKEND control in op_shared_search [rhel-8.10.z]
- Resolves: RHEL-220511 - EMBARGOED CVE-2026-18355 389-ds:1.4/389-ds-base: 389-ds-base: heap buffer overflow via SASL wrapped-record length lower-bound underflow in sasl_io_start_packet() [rhel-8.10.z]
- Resolves: RHEL-232864 - EMBARGOED CVE-2026-18922 389-ds:1.4/389-ds-base: 389-ds-base: SASL PLAIN authentication allows privilege escalation to Directory Manager via stale identity in Cyrus SASL auxiliary property [rhel-8.10.z]
- Resolves: RHEL-244463 - lib389: set nsDS5ReplicaBindDNGroup before ensure_agreement() [rhel-8.10.z]
- Resolves: RHEL-245383 - EMBARGOED CVE-2026-76560 389-ds-base: 389-ds: anonymous LDAP client can defeat SELFDN ACI bind-rule checks via empty bind DN [rhel-8.10.z]
- Resolves: RHEL-248762 - CVE-2026-11770 fix breaks replication total init when nsDS5ReplicaBindDNGroup is set after agreement creation [rhel-8.10.z]
[1.4.3.39-27]
- Bump version to 1.4.3.39-27
- Resolves: RHEL-222326 - EMBARGOED CVE-2026-18453 389-ds:1.4/389-ds-base: 389-ds-base: pre-authentication NULL pointer dereference via paged results and USE_ONE_BACKEND control in op_shared_search [rhel-8.10.z]
- Resolves: RHEL-220511 - EMBARGOED CVE-2026-18355 389-ds:1.4/389-ds-base: 389-ds-base: heap buffer overflow via SASL wrapped-record length lower-bound underflow in sasl_io_start_packet() [rhel-8.10.z]
- Resolves: RHEL-232864 - EMBARGOED CVE-2026-18922 389-ds:1.4/389-ds-base: 389-ds-base: SASL PLAIN authentication allows privilege escalation to Directory Manager via stale identity in Cyrus SASL auxiliary property [rhel-8.10.z]
- Resolves: RHEL-244463 - lib389: set nsDS5ReplicaBindDNGroup before ensure_agreement() [rhel-8.10.z]
- Resolves: RHEL-245383 - EMBARGOED CVE-2026-76560 389-ds-base: 389-ds: anonymous LDAP client can defeat SELFDN ACI bind-rule checks via empty bind DN [rhel-8.10.z]
- Resolves: RHEL-248762 - CVE-2026-11770 fix breaks replication total init when nsDS5ReplicaBindDNGroup is set after agreement creation [rhel-8.10.z]
[1.4.3.39-26]
- Bump version to 1.4.3.39-26
- Resolves: RHEL-183073 - EMBARGOED CVE-2026-11770 389-ds-base: 389-ds-base: pre-auth LDAP filter injection in CleanAllRUV status check [rhel-8.10.z]
- Resolves: RHEL-190782 - CVE-2026-11788 389-ds-base: 389-ds-base: NULL pointer dereference in deref control plugin BER parser [rhel-8.10.z]
- Resolves: RHEL-210880 - EMBARGOED CVE-2026-15722 389-ds:1.4/389-ds-base: 389-ds-base: pre-authentication stack buffer overflow in get_ruvelement_from_berval() via unbounded replica ID parsing [rhel-8.10.z]
[1.4.3.39-25]
- Bump version to 1.4.3.39-25
- Resolves: RHEL-182162 - EMBARGOED CVE-2026-11610 389-ds-base: 389-ds-base: Heap buffer overflow in sasl_io_recv() via padded SASL UNBIND [rhel-8.10.z]
- Resolves: RHEL-183102 - CVE-2026-11774 389-ds-base: 389-ds-base: integer overflow in SASL packet length bypasses size limit
[1.4.3.39-24]
- Bump version to 1.4.3.39-24
- Resolves: RHEL-170278 - Memory leaks in syncrepl plugin during persistent search operations [rhel-8.10.z]
- Resolves: RHEL-163375 - WARN - keys2idl - received NULL idl from index_read_ext_allids
- Resolves: RHEL-159306 - ns-slapd crash in libdb possible memory corruption [rhel-8.10.z]
- Resolves: RHEL-170284 - access log - suspicious wtime optime negative and large values in internal op [rhel-8.10.z]
- Resolves: RHEL-170507 - ns-slapd fails to shutdown when deferred memberof update is in progress [rhel-8.10.z]
- Resolves: RHEL-170509 - Crash in trim_changelog() during the Retro Changelog trimming [rhel-8.10.z]
- Resolves: RHEL-170514 - Possible memory leak when using the Retro Changelog plugin [rhel-8.10.z]
- Resolves: RHEL-170512 - Crash in replica_config_add when manually configuring a replica with an incorrect nsds5ReplicaRoot [rhel-8.10.z]
- Resolves: RHEL-174523 - [RFE] Add OS-level thread names to all server threads [rhel-8.10.z]
- Resolves: RHEL-170483 - test_vlv_recreation_reindex fails on LMDB [rhel-8.10.z]
- Resolves: RHEL-178076 - CVE-2026-9064 389-ds:1.4/389-ds-base: unbounded LDAP controls count in get_ldapmessage_controls_ext() causes CPU and heap amplification (remote DoS) [rhel-8.10.z]
[1.4.3.39-23]
- Resolves: RHEL-137074 - CVE-2025-14905 389-ds:1.4/389-ds-base: 389-ds-base: Remote Code Execution and Denial of Service via heap buffer overflow [rhel-8.10.z]
- Resolves: RHEL-152098 - Scalability issue of replication online initialization with large database [rhel-8.10.z]
[1.4.3.39-22]
- Resolves: RHEL-148485 - Upgrading IDM to latest version: 389-ds-base and ipa-server breaks replication [rhel-8.10.z]
[1.4.3.39-21]
- Resolves: RHEL-141419 - (&(cn:dn:=groups)) no longer returns results [rhel-8.10.z]
- Resolves: RHEL-140272 - ipa-healthcheck is complaining about missing or
incorrectly configured system indexes. [rhel-8.10.z]
[1.4.3.39-20]
- Resolves: RHEL-140086 - Upgrading IDM to latest version: 389-ds-base and ipa-server breaks replication [rhel-8.10.z]
[1.4.3.39-19]
- Resolves: RHEL-117759 - Replication online reinitialization of a large database gets stalled. [rhel-8.10.z]
| CVE-2026-18355 |
| CVE-2026-18453 |
| CVE-2026-18922 |
| CVE-2026-76560 |
| Release/Architecture | Filename | sha256 | Superseded By Advisory | Channel Label |
| Oracle Linux 8 (aarch64) | 389-ds-base-1.4.3.39-28.module+el8.10.0+91024+7bf29691.src.rpm | fcf841694709ad582f2f90aec3f70a3613a0cd6241da798973d53394c6c17eab | - | ol8_aarch64_appstream |
| 389-ds-base-1.4.3.39-28.module+el8.10.0+91024+7bf29691.aarch64.rpm | 74880b874366bf284521dc6c80938db258753f689613c9e25071ea33d432d7f2 | - | ol8_aarch64_appstream | |
| 389-ds-base-devel-1.4.3.39-28.module+el8.10.0+91024+7bf29691.aarch64.rpm | 3a15ef3a6882dbec8eea9e1d955afbbc417c1337678fdec13d48b3cb6f02efbf | - | ol8_aarch64_appstream | |
| 389-ds-base-legacy-tools-1.4.3.39-28.module+el8.10.0+91024+7bf29691.aarch64.rpm | 22fcf8f1a32ed05a07564a141937c35260afbba7ee4aec6b9e5d5da76aa523fc | - | ol8_aarch64_appstream | |
| 389-ds-base-libs-1.4.3.39-28.module+el8.10.0+91024+7bf29691.aarch64.rpm | c3fb9fe427f7071404b014d79ed723a28df753df6d7a75ac7df63065b5d06be9 | - | ol8_aarch64_appstream | |
| 389-ds-base-snmp-1.4.3.39-28.module+el8.10.0+91024+7bf29691.aarch64.rpm | 7e7d3b6a227a2bb7f294f3c234dced288f34f07669c4b117b8a31eb01c806435 | - | ol8_aarch64_appstream | |
| python3-lib389-1.4.3.39-28.module+el8.10.0+91024+7bf29691.noarch.rpm | 4d454b5319b53afa330c9a314e7ca5546a9fd75a8ad68dfc4f090dd2cf60522e | - | ol8_aarch64_appstream | |
| Oracle Linux 8 (x86_64) | 389-ds-base-1.4.3.39-28.module+el8.10.0+91024+7bf29691.src.rpm | fcf841694709ad582f2f90aec3f70a3613a0cd6241da798973d53394c6c17eab | - | ol8_x86_64_appstream |
| 389-ds-base-1.4.3.39-28.module+el8.10.0+91024+7bf29691.x86_64.rpm | 0ea38648b7bf65c18d0eca6b022c8de206fc8dcdf0c78907462ab287e5051ccc | - | ol8_x86_64_appstream | |
| 389-ds-base-devel-1.4.3.39-28.module+el8.10.0+91024+7bf29691.x86_64.rpm | 4fb06b91a3a721671f739899c1c92d8d993854c9e50dc9db3cfb6a422809d988 | - | ol8_x86_64_appstream | |
| 389-ds-base-legacy-tools-1.4.3.39-28.module+el8.10.0+91024+7bf29691.x86_64.rpm | b2d7c6d8b102cdb44359a299da439487100592673971a5a4416e0d80c9ae9657 | - | ol8_x86_64_appstream | |
| 389-ds-base-libs-1.4.3.39-28.module+el8.10.0+91024+7bf29691.x86_64.rpm | a4d1754cbefe8d060a9865469c8104cef823705ecb8b876c911f6bfe9f21b1a9 | - | ol8_x86_64_appstream | |
| 389-ds-base-snmp-1.4.3.39-28.module+el8.10.0+91024+7bf29691.x86_64.rpm | 27c3ee59aa3d4106a726e8ff40f66ced9b78fde14d4aba3f87bb40688978bd4c | - | ol8_x86_64_appstream | |
| python3-lib389-1.4.3.39-28.module+el8.10.0+91024+7bf29691.noarch.rpm | 4d454b5319b53afa330c9a314e7ca5546a9fd75a8ad68dfc4f090dd2cf60522e | - | ol8_x86_64_appstream | |
This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team