SUSE-CU-2026:11438-1: Security update of suse/389-ds

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Sat Oct 3 09:31:52 UTC 2026


SUSE Container Update Advisory: suse/389-ds
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:11438-1
Container Tags        : suse/389-ds:3.0 , suse/389-ds:3.0.7 , suse/389-ds:3.0.7-18.14 , suse/389-ds:latest
Container Release     : 18.14
Severity              : critical
Type                  : security
References            : 1262263 1264713 1267631 1268572 1268573 1271272 1273133 1275096
                        1275594 1275732 1275859 1275860 1275915 1279572 1279864 1279865
                        1279866 1279867 1280941 CVE-2026-11770 CVE-2026-18355 CVE-2026-18453
                        CVE-2026-18922 CVE-2026-19843 CVE-2026-41080 CVE-2026-45186 CVE-2026-50219
                        CVE-2026-56131 CVE-2026-56132 CVE-2026-56403 CVE-2026-56404 CVE-2026-56405
                        CVE-2026-56406 CVE-2026-56407 CVE-2026-56408 CVE-2026-56409 CVE-2026-56410
                        CVE-2026-56411 CVE-2026-56412 CVE-2026-66046 CVE-2026-72522 CVE-2026-76560
                        CVE-2026-76641 CVE-2026-76956 CVE-2026-76957 
-----------------------------------------------------------------

The container suse/389-ds was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: 1754
Released:    Thu Sep 24 09:07:13 2026
Summary:     Security update for expat
Type:        security
Severity:    important
References:  1262263,1264713,1267631,1268572,1268573,1275096,1275594,1275732,1275859,1275860,1275915,CVE-2026-41080,CVE-2026-45186,CVE-2026-50219,CVE-2026-56131,CVE-2026-56132,CVE-2026-56403,CVE-2026-56404,CVE-2026-56405,CVE-2026-56406,CVE-2026-56407,CVE-2026-56408,CVE-2026-56409,CVE-2026-56410,CVE-2026-56411,CVE-2026-56412,CVE-2026-66046,CVE-2026-72522,CVE-2026-76641,CVE-2026-76956,CVE-2026-76957
This update for expat fixes the following issues:

- CVE-2026-41080: crafted XML document can cause a denial of service (bsc#1262263).
- CVE-2026-45186: In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a
  denial of service via moderately sized crafted XML input (bsc#1264713).
- CVE-2026-50219: libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse,
  XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation (bsc#1267631).
- CVE-2026-56131: libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within
  handlers in cases of a policy violation (bsc#1268572).
- CVE-2026-56132: mishandled memory reallocation during array scaffolding in doProlog can cause heap-based buffer
  overflows (bsc#1268573).
- CVE-2026-56403: integer overflow in the storeAtts function can cause memory corruption and potential arbitrary code
  execution (bsc#1275096).
- CVE-2026-56404: integer overflow in the addBinding function can cause undersized memory allocations, memory
  corruption, and application crashes (bsc#1275096).
- CVE-2026-56405: integer overflow in the getAttributeId function can cause heap memory corruption and arbitrary
  code execution (bsc#1275096).
- CVE-2026-56406: missing bounds validation in XML_ParseBuffer can cause integer overflows, memory corruption, and
  application crashes (bsc#1275096).
- CVE-2026-56407: integer overflow in doProlog related to entity text length can cause memory corruption and denial
  of service (bsc#1275096).
- CVE-2026-56408: integer overflow in the copyString function can cause heap memory corruption and application crashes
  (bsc#1275096).
- CVE-2026-56409: integer overflow in the xmlwf utility output filename handling can allow path buffer corruption and
  arbitrary file write conditions (bsc#1275096).
- CVE-2026-56410: integer overflow in resolveSystemId within the xmlwf utility can cause memory corruption, information
  disclosure, and potential code execution (bsc#1275096).
- CVE-2026-56411: integer overflow in endDoctypeDecl via NOTATION declarations in xmlwf can cause memory corruption and
  denial of service (bsc#1275096).
- CVE-2026-56412: incomplete handler call depth tracking in doCdataSection can cause use-after-free
  conditions and arbitrary code execution (bsc#1275096).
- CVE-2026-66046: libexpat: denial of service vulnerability caused by quadratic algorithmic complexity in the
  storeAtts() function in xmlparse.c (bsc#1275732).
- CVE-2026-72522: libexpat: out-of-bounds read and resultant infinite loop due to low surrogates being treated the same
  as high surrogates during Unicode processing (bsc#1275594).
- CVE-2026-76641: Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger
  memory corruption (bsc#1275915).
- CVE-2026-76956: In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to
  insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via
  crafted X (bsc#1275860).
- CVE-2026-76957: libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. (bsc#1275859).

Changes for expat:

- Updated to version 2.8.4

-----------------------------------------------------------------
Advisory ID: 1759
Released:    Thu Sep 24 11:24:13 2026
Summary:     Security update for 389-ds
Type:        security
Severity:    critical
References:  1273133,1279572,1279864,1279865,1279866,1279867,CVE-2026-11770,CVE-2026-18355,CVE-2026-18453,CVE-2026-18922,CVE-2026-19843,CVE-2026-76560
This update for 389-ds fixes the following issues:

- CVE-2026-11770: pre-auth LDAP filter injection in CleanAllRUV status check (bsc#1273133).
- CVE-2026-18355: heap buffer overflow in the SASL I/O layer allows a remote authenticated attacker to cause a denial of
  service or potentially achieve remote code execution (bsc#1279864).
- CVE-2026-18453: 389-ds-base: 389-ds-base: pre-authentication NULL pointer dereference via paged results and
  USE_ONE_BACKEND control in op_shared_search (bsc#1279572).
- CVE-2026-18922: stale identity carried in a Cyrus SASL auxiliary property during SASL PLAIN authentication allows
  unauthenticated attackers to achieve privilege escalation to Directory Manager (bsc#1279865).
- CVE-2026-19843: unescaped LDAP DN in Cockpit 389 Console LDAP editor allows an LDAP user with delegated privileges to
  execute shell commands with root privileges on the directory server host (bsc#1279866).
- CVE-2026-76560: incorrect matching in the SELFDN ACI bind-rule evaluator allows an anonymous LDAP client to bypass
  access controls on directory entries containing empty SELFDN attributes (bsc#1279867).

Changes for 389-ds:

- Update to version 3.0.7~git2.2846d5288:

 * Issue 7757 - stack-buffer-overflow caused by slapi_attr_init_syntax() (#7759)
 * Issue 7796 - A large received replicaID can overflow the storage buffer (#7797)
 * Issue 7041 - Add WebUI test for group member management (#7111)
 * Issue 7808 - CI - harden online_import_nosync_test (#7809)
 * Issue 7611 - PBKDF2 password verification should reject invalid iteration counts (#7632) (#7812)
 * [Backport 389-ds-base-3.0] Update rust-dependencies (#7799)
 * Issue 7595 - Remove the nightly dedup gate and fix dispatched test runs
 * Fix expiration time check (#7718)
 * Issue 7774 - Add backport action (#7775)
 * Issue 7770 - Testimony failure in test_cleanruv_extop_security.py (#7771)
 * Issue 3082 - Add test389.topologies compatibility shim for backports (#7725)
 * Issue 7595 - Skip redundant CI runs to relieve the Actions queue (#7749)
 * Issue 7760 - CI - harden dsconf_task_test.py
 * Issue 4701 - Fix UAF when excluding attrs from retro changelog (#7730)
 * Issue 7723 - Range search returns an empty result when its start key is removed (#7724)
 * Issue 7639 - Move log compression outside of global write lock
 * Issue 7631 - Don't install bpftrace by default (#7726)
 * Issue 7735 - Heap overflow when parsing objectclass superior (#7736)
 * Issue 7733 - Typo about nsuniqueid in tombstone_to_conflict (#7734)
 * Issue 7707 - lib389: set nsDS5ReplicaBindDNGroup before ensure_agreement() in join_supplier/hub/consumer (#7708)

-----------------------------------------------------------------
Advisory ID: 1762
Released:    Fri Sep 25 11:09:47 2026
Summary:     Recommended update for tar
Type:        recommended
Severity:    moderate
References:  1271272,1280941
This update for tar fixes the following issues:

Changes in tar:

- Fixes tar incorrectly skipping members in certain archives containing
  dirs with non-zero sizes. (bsc#1271272)
- Avoid acl_ prefix for functions:
    * The acl.h header from libacl uses acl_ prefix for its functions.
      Avoid defining functions with the same name in order to protect its namespace. (bsc#1280941)


The following package changes have been done:

- libexpat1-2.8.4-160000.1.1 updated
- tar-1.35-160000.5.1 updated
- libsvrcore0-3.0.7~git2.2846d5288-160000.1.1 updated
- lib389-3.0.7~git2.2846d5288-160000.1.1 updated
- 389-ds-3.0.7~git2.2846d5288-160000.1.1 updated
- container:bci-bci-base-16.0-b83d6d585765c2f6aacfa37676547be3e9c2c36fa6b0c7b3f8abdc9ff31f8310-0 updated
- container:registry.suse.com-bci-bci-micro-16.0-46b3f28a6ade6e6ff39d13ee8e50d3bd1b241d037b9702364dc35000188fbb36-0 updated


More information about the sle-container-updates mailing list