ELSA-2026-64785-0

ELSA-2026-64785-0 - 389-ds-base security, bug fix, and enhancement update

Type:SECURITY
Impact:CRITICAL
Release Date:2026-09-08

Description


[3.2.0-10]
- Bump version to 3.2.0-10
- Resolves: RHEL-220500 - CVE-2026-18355 389-ds-base: heap buffer overflow
via SASL wrapped-record length lower-bound underflow in
sasl_io_start_packet() [rhel-10.2.z]
- Resolves: RHEL-222320 - CVE-2026-18453 389-ds-base: pre-authentication
NULL pointer dereference via paged results and USE_ONE_BACKEND control in
op_shared_search [rhel-10.2.z]
- Resolves: RHEL-232863 - CVE-2026-18922 389-ds-base: SASL PLAIN
authentication allows privilege escalation to Directory Manager via stale
identity in Cyrus SASL auxiliary property [rhel-10.2.z]
- Resolves: RHEL-244470 - lib389: set nsDS5ReplicaBindDNGroup before
ensure_agreement() [rhel-10.2.z]
- Resolves: RHEL-245372 - CVE-2026-76560 389-ds-base: anonymous LDAP client
can defeat SELFDN ACI bind-rule checks via empty bind DN [rhel-10.2.z]
- Resolves: RHEL-247859 - CVE-2026-78701 389-ds-base: CVE-2026-11610
incomplete fix may introduce a connection-stall DoS [rhel-10.2.z]
- Resolves: RHEL-248770 - CVE-2026-11770 fix breaks replication total init
when nsDS5ReplicaBindDNGroup is set after agreement creation
[rhel-10.2.z]


Related CVEs


CVE-2026-18355
CVE-2026-18453
CVE-2026-18922
CVE-2026-76560
CVE-2026-78701

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 10 (aarch64) 389-ds-base-3.2.0-10.el10_2.src.rpmf6201f7aa0f0145ce698f77da69199b2566b4f5b07684c32a024c1df2577bf3e-ol10_aarch64_appstream
389-ds-base-3.2.0-10.el10_2.src.rpmf6201f7aa0f0145ce698f77da69199b2566b4f5b07684c32a024c1df2577bf3e-ol10_aarch64_codeready_builder
389-ds-base-3.2.0-10.el10_2.aarch64.rpm1d8e36c2291ae3172f2b2a7e23a354ba91a17778d86e6f935293862e28b029dd-ol10_aarch64_appstream
389-ds-base-bdb-3.2.0-10.el10_2.aarch64.rpm998bb014d684af227a526c25aff271dc49bf126e3eed0b207b407117bc84436d-ol10_aarch64_codeready_builder
389-ds-base-devel-3.2.0-10.el10_2.aarch64.rpmb35008f1a08d69a392b9aa5dad63090b6f5d82bc023bc4e22c830691416c64f1-ol10_aarch64_codeready_builder
389-ds-base-libs-3.2.0-10.el10_2.aarch64.rpm74117cda37003551efa18bd4b45907c757cf8569fd1c396683d221a55e62ab7c-ol10_aarch64_appstream
389-ds-base-snmp-3.2.0-10.el10_2.aarch64.rpm98495eb0ca9d60852ece19b9612f07564c9fefd249fce1e09473711fe8a44d54-ol10_aarch64_appstream
python3-lib389-3.2.0-10.el10_2.noarch.rpmc2985a8223a90f31c5fa991647b3fa0def7178bd0afbaea50c60da2df3886c0d-ol10_aarch64_appstream
Oracle Linux 10 (x86_64) 389-ds-base-3.2.0-10.el10_2.src.rpmf6201f7aa0f0145ce698f77da69199b2566b4f5b07684c32a024c1df2577bf3e-ol10_x86_64_appstream
389-ds-base-3.2.0-10.el10_2.src.rpmf6201f7aa0f0145ce698f77da69199b2566b4f5b07684c32a024c1df2577bf3e-ol10_x86_64_codeready_builder
389-ds-base-3.2.0-10.el10_2.x86_64.rpm891fc30425faf6b0659651f340455db0ce561a2511609f22df251f384f90b03a-ol10_x86_64_appstream
389-ds-base-bdb-3.2.0-10.el10_2.x86_64.rpmfb06eaff6030d07a831028b0d02dbfea7a77c62b0f5a0fd4266231c5e46cfefa-ol10_x86_64_codeready_builder
389-ds-base-devel-3.2.0-10.el10_2.x86_64.rpm9f2f3ca7d8af32c160c5e41b8ab5510b2757256a77954668f9b2c17d8e59a93b-ol10_x86_64_codeready_builder
389-ds-base-libs-3.2.0-10.el10_2.x86_64.rpm56ffdad7367fe8661e8572b565783fa38a01403286f79468f3de5536afc3c6a1-ol10_x86_64_appstream
389-ds-base-snmp-3.2.0-10.el10_2.x86_64.rpm2431921cc59f04468729dfaa55106b5a52401c4f081d3ba481fa613832bd5d3c-ol10_x86_64_appstream
python3-lib389-3.2.0-10.el10_2.noarch.rpmc2985a8223a90f31c5fa991647b3fa0def7178bd0afbaea50c60da2df3886c0d-ol10_x86_64_appstream



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete