SUSE-SU-2026:3137-1: important: Security update for 389-ds
SLE-SECURITY-UPDATES
null at suse.de
Mon Jul 20 20:42:42 UTC 2026
# Security update for 389-ds
Announcement ID: SUSE-SU-2026:3137-1
Release Date: 2026-07-20T15:10:33Z
Rating: important
References:
* bsc#1267975
* bsc#1268041
* bsc#1268046
* bsc#1268047
* bsc#1268057
* bsc#1268058
* bsc#1268060
* bsc#1268062
* bsc#1268064
* bsc#1268065
* bsc#1268115
* bsc#1268298
* bsc#1268491
* bsc#1269120
* bsc#1270695
Cross-References:
* CVE-2026-11610
* CVE-2026-11611
* CVE-2026-11774
* CVE-2026-11785
* CVE-2026-11786
* CVE-2026-11787
* CVE-2026-11788
* CVE-2026-11789
* CVE-2026-11790
* CVE-2026-11791
* CVE-2026-11792
* CVE-2026-11793
* CVE-2026-11884
* CVE-2026-12528
CVSS scores:
* CVE-2026-11610 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-11610 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-11611 ( SUSE ): 7.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-11611 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-11611 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-11774 ( SUSE ): 7.2
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N
* CVE-2026-11774 ( SUSE ): 7.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
* CVE-2026-11774 ( NVD ): 7.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
* CVE-2026-11774 ( NVD ): 7.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
* CVE-2026-11785 ( SUSE ): 5.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-11785 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-11785 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-11786 ( SUSE ): 5.9
CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-11786 ( SUSE ): 5.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H
* CVE-2026-11786 ( NVD ): 1.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-11786 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-11787 ( SUSE ): 2.3
CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
* CVE-2026-11787 ( SUSE ): 5.0 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
* CVE-2026-11787 ( NVD ): 5.0 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
* CVE-2026-11787 ( NVD ): 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
* CVE-2026-11788 ( SUSE ): 8.2
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-11788 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-11788 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-11788 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-11789 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-11789 ( SUSE ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-11789 ( NVD ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-11789 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-11790 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-11790 ( SUSE ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-11790 ( NVD ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-11791 ( SUSE ): 5.9
CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N
* CVE-2026-11791 ( SUSE ): 5.5 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:H
* CVE-2026-11791 ( NVD ): 5.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H
* CVE-2026-11791 ( NVD ): 5.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H
* CVE-2026-11792 ( SUSE ): 2.1
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
* CVE-2026-11792 ( SUSE ): 3.3 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L
* CVE-2026-11792 ( NVD ): 3.3 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L
* CVE-2026-11793 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-11793 ( SUSE ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-11793 ( NVD ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-11884 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
* CVE-2026-11884 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
* CVE-2026-12528 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
* CVE-2026-12528 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
* CVE-2026-12528 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Affected Products:
* openSUSE Leap 15.5
* SUSE Linux Enterprise High Performance Computing 15 SP5
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
* SUSE Linux Enterprise Server 15 SP5
* SUSE Linux Enterprise Server 15 SP5 LTSS
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
An update that solves 14 vulnerabilities and has one security fix can now be
installed.
## Description:
This update for 389-ds fixes the following issues:
Update to version 2.2.10~git255.752643c78.
Security issues fixed:
* CVE-2026-11610: missing bounds check in `sasl_io_recv()` can lead to a heap
buffer overflow when processing a specially crafted oversized LDAP UNBIND
packet (bsc#1270695).
* CVE-2026-11611: Content Synchronization persistent search plugin allows
unbounded memory growth when an authenticated client stops reading sync
responses(bsc#1267975).
* CVE-2026-11774: integer overflow in `sasl_io_start_packet()` can lead to
heap buffer overflow when processing a crafted SASL packet length prefix
(bsc#1268298).
* CVE-2026-11785: type confusion in the SSO token handler can cause partial
stack address information disclosure in LDA responses (bsc#1268065).
* CVE-2026-11786: out-of-bounds read in the LDIF parser when processing
attribute types with trailing semicolons during database import
(bsc#1268064).
* CVE-2026-11787: missing bounds check in the `ldap_utf8prev()` functioncan
can lead to a heap buffer overread in string filter parsing(bsc#1268062).
* CVE-2026-11788: missing allocation check in the dereference control plugin
before using a BER structure can lead to LDAP server crash when the system
is under memory pressure (bsc#1268057).
* CVE-2026-11789: integer underflow in the SMD5 password storage plugin can
lead to a buffer overread when computing salt length from a crafted password
hash shorter than 16 bytes (bsc#1268058).
* CVE-2026-11790: improper bounds enforcement in the BKDF2-SHA256 password
storage plugin can lead to excessive resource consumption during
authentication and cause a DoS (bsc#1268060).
* CVE-2026-11791: use-after-free in the schema reload mechanism can lead to a
`ns-slapd` crash when concurrent LDAP query traffic is active (bsc#1268047).
* CVE-2026-11792: missing checks in `create_masked_entry_string` can lead to a
heap and log output corruption whe a short cleartext password is logged
(bsc#1268046).
* CVE-2026-11793: missing bounds check in `checkPrefix()` can lead to a stack
buffer overflow when processing an algorithm ID during parsing of
reversible-encrypted attribute values (bsc#1268041).
* CVE-2026-11884: improper string management can lead to heap buffer overflow
when serializing objectclass definitions (bsc#1268115).
* CVE-2026-12528: missing length checks in the `__aclp__normalize_acltxt()`
function can lead to heap buffer overflow when processing a malformed ACI
string (bsc#1268491).
Other updates and bugfixes:
* Version 2.2.10~git255.752643c78.
* Issue 7406 - Fix `ldap-agent` SNMP stats file loading (#7630)
* Issue 7621 - Stack Buffer Overflow in Password `checkPrefix`
* Issue 7623 - Heap Buffer Overflow in `389-ds-base` Audit Log Password
Masking
* Issue 6625 - Backport `get_pid` to fix `check_asan_report` (#7625)
* Issue 7602 - CI - `lib389` user compare fails due to parentid mismatch
(#7603)
* Issue 7537 - CI - Fix replication log monitoring parser/timing failures
(#7592)
* Issue 7593 - Fix testimony docstring for SASL overflow test (#7606)
* Issue 7530 - CI - Stabilize DNA plugin replication tests timing out in CI
(#7572)
* Issue 7593 - Reject invalid SASL packet length values in
`sasl_io_start_packet` (#7594)
* Issue 3555 - UI - Fix audit issue with `npm` \- `ws`, `js-yaml`, `js-yaml` ,
`postcss`, `uuid`
* Issue 7541 - Add invalid ACL text header regression test (#7591)
* Issue 7541 - heap-buffer-overflows in `__aclp__normalize_acltxt()` (#7542)
* Issue 7576 - Fix leak of temporary attribute syntax hash tables after schema
reload
* Issue 7558 - During online import, the IDL should be created with in-depth
first approach (#7559)
* Issue 7500 - Prevent unsigned integer underflow during stalled import
* Issue 7560 - `lib389` \- Add helper function for checking ASAN files
* Issue 7539 - Server shutdown during online reindex may lead to data loss
(#7540)
* Issue 7549 - Substring index should validate minimum
`nsSubStrBegin`/`nsSubStrEnd` values (#7550)
* Issue 7440 - Substring index produces empty results and can crash when non-
default `nsSubStrBegin`/`nsSubStrEnd` lengths are configured (#7441)
* Fix test389 imports on older branches
* Issue 7437 - `LeakSanitizer`: memory leaks in CoS cache error paths (#7438)
* Issue 6922 - `AddressSanitizer`: leaks found by acl test suite
* Issue 3555 - UI - Fix audit issue with `npm` \- `brace-expansion` (#7556)
* Issue 7554 - deref plugin null pointer dereference if `ber_init` fails
* Issue 7514 - Crash when doing moddn on very large subtree
* Issue 7516 - `dblayer_bulk_nextdata` should not return an error when
maxrecords is hit
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3137=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3137=1
* SUSE Linux Enterprise Server 15 SP5 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3137=1
* openSUSE Leap 15.5
zypper in -t patch SUSE-2026-3137=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3137=1
## Package List:
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64
x86_64)
* lib389-2.2.10~git255.752643c78-150500.3.48.1
* libsvrcore0-debuginfo-2.2.10~git255.752643c78-150500.3.48.1
* 389-ds-debugsource-2.2.10~git255.752643c78-150500.3.48.1
* 389-ds-devel-2.2.10~git255.752643c78-150500.3.48.1
* 389-ds-debuginfo-2.2.10~git255.752643c78-150500.3.48.1
* 389-ds-2.2.10~git255.752643c78-150500.3.48.1
* libsvrcore0-2.2.10~git255.752643c78-150500.3.48.1
* openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64)
* 389-ds-snmp-debuginfo-2.2.10~git255.752643c78-150500.3.48.1
* lib389-2.2.10~git255.752643c78-150500.3.48.1
* libsvrcore0-debuginfo-2.2.10~git255.752643c78-150500.3.48.1
* 389-ds-devel-2.2.10~git255.752643c78-150500.3.48.1
* 389-ds-snmp-2.2.10~git255.752643c78-150500.3.48.1
* 389-ds-debugsource-2.2.10~git255.752643c78-150500.3.48.1
* 389-ds-debuginfo-2.2.10~git255.752643c78-150500.3.48.1
* 389-ds-2.2.10~git255.752643c78-150500.3.48.1
* libsvrcore0-2.2.10~git255.752643c78-150500.3.48.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64)
* lib389-2.2.10~git255.752643c78-150500.3.48.1
* libsvrcore0-debuginfo-2.2.10~git255.752643c78-150500.3.48.1
* 389-ds-devel-2.2.10~git255.752643c78-150500.3.48.1
* 389-ds-debugsource-2.2.10~git255.752643c78-150500.3.48.1
* 389-ds-debuginfo-2.2.10~git255.752643c78-150500.3.48.1
* 389-ds-2.2.10~git255.752643c78-150500.3.48.1
* libsvrcore0-2.2.10~git255.752643c78-150500.3.48.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64
x86_64)
* lib389-2.2.10~git255.752643c78-150500.3.48.1
* libsvrcore0-debuginfo-2.2.10~git255.752643c78-150500.3.48.1
* 389-ds-devel-2.2.10~git255.752643c78-150500.3.48.1
* 389-ds-debugsource-2.2.10~git255.752643c78-150500.3.48.1
* 389-ds-debuginfo-2.2.10~git255.752643c78-150500.3.48.1
* 389-ds-2.2.10~git255.752643c78-150500.3.48.1
* libsvrcore0-2.2.10~git255.752643c78-150500.3.48.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64)
* lib389-2.2.10~git255.752643c78-150500.3.48.1
* libsvrcore0-debuginfo-2.2.10~git255.752643c78-150500.3.48.1
* 389-ds-devel-2.2.10~git255.752643c78-150500.3.48.1
* 389-ds-debugsource-2.2.10~git255.752643c78-150500.3.48.1
* 389-ds-debuginfo-2.2.10~git255.752643c78-150500.3.48.1
* 389-ds-2.2.10~git255.752643c78-150500.3.48.1
* libsvrcore0-2.2.10~git255.752643c78-150500.3.48.1
## References:
* https://www.suse.com/security/cve/CVE-2026-11610.html
* https://www.suse.com/security/cve/CVE-2026-11611.html
* https://www.suse.com/security/cve/CVE-2026-11774.html
* https://www.suse.com/security/cve/CVE-2026-11785.html
* https://www.suse.com/security/cve/CVE-2026-11786.html
* https://www.suse.com/security/cve/CVE-2026-11787.html
* https://www.suse.com/security/cve/CVE-2026-11788.html
* https://www.suse.com/security/cve/CVE-2026-11789.html
* https://www.suse.com/security/cve/CVE-2026-11790.html
* https://www.suse.com/security/cve/CVE-2026-11791.html
* https://www.suse.com/security/cve/CVE-2026-11792.html
* https://www.suse.com/security/cve/CVE-2026-11793.html
* https://www.suse.com/security/cve/CVE-2026-11884.html
* https://www.suse.com/security/cve/CVE-2026-12528.html
* https://bugzilla.suse.com/show_bug.cgi?id=1267975
* https://bugzilla.suse.com/show_bug.cgi?id=1268041
* https://bugzilla.suse.com/show_bug.cgi?id=1268046
* https://bugzilla.suse.com/show_bug.cgi?id=1268047
* https://bugzilla.suse.com/show_bug.cgi?id=1268057
* https://bugzilla.suse.com/show_bug.cgi?id=1268058
* https://bugzilla.suse.com/show_bug.cgi?id=1268060
* https://bugzilla.suse.com/show_bug.cgi?id=1268062
* https://bugzilla.suse.com/show_bug.cgi?id=1268064
* https://bugzilla.suse.com/show_bug.cgi?id=1268065
* https://bugzilla.suse.com/show_bug.cgi?id=1268115
* https://bugzilla.suse.com/show_bug.cgi?id=1268298
* https://bugzilla.suse.com/show_bug.cgi?id=1268491
* https://bugzilla.suse.com/show_bug.cgi?id=1269120
* https://bugzilla.suse.com/show_bug.cgi?id=1270695
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.suse.com/pipermail/sle-security-updates/attachments/20260720/7fa1e79c/attachment.htm>
More information about the sle-security-updates
mailing list