SUSE-SU-2026:4380-1: critical: Security update for 389-ds

SLE-SECURITY-UPDATES null at suse.de
Mon Sep 28 20:33:17 UTC 2026


# Security update for 389-ds

Announcement ID: SUSE-SU-2026:4380-1  
Release Date: 2026-09-28T15:18:15Z  
Rating: critical  
References:

  * bsc#1273133
  * bsc#1279572
  * bsc#1279864
  * bsc#1279865
  * bsc#1279866
  * bsc#1279867
  * jsc#PED-16949

  
Cross-References:

  * CVE-2026-11770
  * CVE-2026-18355
  * CVE-2026-18453
  * CVE-2026-18922
  * CVE-2026-19843
  * CVE-2026-76560

  
CVSS scores:

  * CVE-2026-11770 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  * CVE-2026-11770 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  * CVE-2026-18355 ( SUSE ):  7.7
    CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-18355 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-18355 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-18453 ( SUSE ):  6.9
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
  * CVE-2026-18453 ( SUSE ):  5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
  * CVE-2026-18453 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-18922 ( SUSE ):  9.3
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-18922 ( SUSE ):  9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-18922 ( NVD ):  9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-19843 ( SUSE ):  8.6
    CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-19843 ( SUSE ):  8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
  * CVE-2026-19843 ( NVD ):  8.4 CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
  * CVE-2026-76560 ( SUSE ):  8.8
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-76560 ( SUSE ):  8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
  * CVE-2026-76560 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

  
Affected Products:

  * Server Applications Module 15-SP7
  * SUSE Linux Enterprise Real Time 15 SP7
  * SUSE Linux Enterprise Server 15 SP7
  * SUSE Linux Enterprise Server for SAP Applications 15 SP7

  
  
An update that solves six vulnerabilities and contains one feature can now be
installed.

## Description:

This update for 389-ds fixes the following issues:

  * CVE-2026-11770: pre-auth LDAP filter injection in CleanAllRUV status check
    (bsc#1273133).
  * CVE-2026-18355: heap buffer overflow in the SASL I/O layer allows a remote
    authenticated attacker to cause a denial of service or potentially achieve
    remote code execution (bsc#1279864).
  * CVE-2026-18453: 389-ds-base: 389-ds-base: pre-authentication NULL pointer
    dereference via paged results and USE_ONE_BACKEND control in
    op_shared_search (bsc#1279572).
  * CVE-2026-18922: stale identity carried in a Cyrus SASL auxiliary property
    during SASL PLAIN authentication allows unauthenticated attackers to achieve
    privilege escalation to Directory Manager (bsc#1279865).
  * CVE-2026-19843: unescaped LDAP DN in Cockpit 389 Console LDAP editor allows
    an LDAP user with delegated privileges to execute shell commands with root
    privileges on the directory server host (bsc#1279866).
  * CVE-2026-76560: incorrect matching in the SELFDN ACI bind-rule evaluator
    allows an anonymous LDAP client to bypass access controls on directory
    entries containing empty SELFDN attributes (bsc#1279867).

Changes for 389-ds:

  * Update to version 2.8 LTS (jsc#PED-16949).

  * Update to version 2.8.2~git10.030ada7a6:

  * Issue 6596 - BUG - Compilation Regresion (#6597) (#7866)
  * Issue 7627 - When it exists configured matching rule for an (#7628)
  * [Backport 389-ds-base-2.8] Issue 7611 - PBKDF2 password verification should
    reject invalid iteration counts (#7852)
  * iadvisories/GHSA-rgxx-hcc4-x3h4 / heap-buffer-overflow in rdn_av_swap
    (#7826)
  * Migrate pwdchan to base64 0.23 Engine API
  * Update rust-dependencies
  * Issue 7823 - CI: stabilize test_controltype_expired_grace_limit (#7824)
  * Issue 7815 - Support nsslapd-attribute-name-exceptions when adding entries
  * Issue 7757 - stack-buffer-overflow caused by slapi_attr_init_syntax()
    (#7759)
  * Issue 7796 - A large received replicaID can overflow the storage buffer
    (#7797)
  * Issue 7041 - Add WebUI test for group member management (#7111)
  * Issue 7808 - CI - harden online_import_nosync_test (#7809)
  * Issue 7595 - Remove the nightly dedup gate and fix dispatched test runs
  * Fix expiration time check (#7718)
  * Issue 7774 - Add backport action (#7775)
  * Issue 7770 - Testimony failure in test_cleanruv_extop_security.py (#7771)
  * Issue 3082 - Add test389.topologies compatibility shim for backports (#7725)
  * Issue 7595 - Skip redundant CI runs to relieve the Actions queue (#7751)
  * Issue 7760 - CI - harden dsconf_task_test.py
  * Issue 4701 - Fix UAF when excluding attrs from retro changelog (#7730)
  * Issue 7723 - Range search returns an empty result when its start key is
    removed (#7724)
  * Issue 7735 - Heap overflow when parsing objectclass superior (#7736)
  * Issue 7733 - Typo about nsuniqueid in tombstone_to_conflict (#7734)
  * Issue 7284 - Creating local password policy succeeds with incorrect
    passwordInHistory value (#7662)
  * Issue 7284 - Automated test for creating local password policy with
    incorrect passwordInHistory value (#7608)
  * Issue 7284 - CI - Fix test_grace_limit_section after pwpolicy validation fix
    (#7357)
  * Issue 7284 - Creating local password policy succeeds with incorrect
    passwordInHistory value (#7285)
  * Issue 7707 - lib389: set nsDS5ReplicaBindDNGroup before ensure_agreement()
    in join_supplier/hub/consumer (#7708)
  * Issue 7711 - Fix typo in accountpolicy --login-history-size help text
    (#7713)
  * Issue 7688 - BUG - partial address leak in sso token (#7689)
  * Issue 7705 - With memberOfEntryScope set, deferred memberOf skips MODIFY
    operations (#7706)
  * Issue 7698 - Fix silent entry loss in LMDB bulk import waiter handling
    (#7699)
  * Issue 7666 - Replication performance degradation during total init on high-
    latency storage (#7667)
  * Issue 7201 - Syscall overhead in LMDB import writer thread (#7204)
  * Issue 7645 - Add runtime LeakSanitizer leak check (#7646)
  * Issue 7714 - UI - sass import rules are deprecated
  * Issue 7658 - Heap Buffer Overflow in sasl_io_recv() via Padded SASL UNBIND
  * Issue 7710 - MemberOf deferred update - Use condvar instead of sleep loop
  * Issue 7637 - fix cherry-pick error
  * Issue 7637 - UI - Using Arrow Keys in New Object Wizard Resulted in DOM
    Reload
  * Issue 7578 - schema - attribute refcount is not maintained properly
  * Issue 7605 - Harden CI test ports against ephemeral allocation (#7692)
  * Issue 7528 - Retry the CI image pull instead of failing the job (#7691)
  * Issue 7460 - MOD_REPLACE on groups/link attributes modifies overlap targets
    (#7461)
  * Issue 7670 - BDB range searches intermittently fail with err=1 under write
    load (#7671)
  * Issue 7108 - Fix shutdown crash in entry cache destruction (#7163)
  * Issue 7200 - repl-agmt create doesn't set some parameters (#7663)
  * Issue 7611 - Preserve legacy PBKDF2 hash compatibility (#7649)
  * Issue 7547 - Heap buffer overflow in ldap_utf8prev()
  * Issue 7611 - PBKDF2 password verification should reject invalid iteration
    count (#7613)
  * Issue 7558 - Total init sends the suffix entry twice (#7640)
  * Issue 7635 - Integer Underflow in {SMD5} Password Comparison (#7636)
  * Issue 7406 - Fix ldap-agent SNMP stats file loading (#7630)
  * Issue 7621 - Stack Buffer Overflow in Password checkPrefix
  * Issue 7623 - Heap Buffer Overflow in 389-ds-base Audit Log Password Masking
  * Issue 7602 - CI - lib389 user compare fails due to parentid mismatch (#7603)
  * Issue 7537 - CI - Fix replication log monitoring parser/timing failures
    (#7592)
  * Issue 7593 - Fix testimony docstring for SASL overflow test (#7606)
  * Issue 7530 - CI - Stabilize DNA plugin replication tests timing out in CI
    (#7572)
  * Issue 7593 - Reject invalid SASL packet length values in
    sasl_io_start_packet (#7594)
  * Issue 3555 - UI - Fix audit issue with npm - ws, js-yaml, js-yaml, postcss,
    uuid
  * Issue 7541 - Add invalid ACL text header regression test (#7591)
  * Issue 7541 - heap-buffer-overflows in __aclp__normalize_acltxt() (#7542)
  * Issue 7576 - Fix leak of temporary attribute syntax hash tables after schema
    reload
  * Issue 7198 - Web console doesn't show sub-suffix when parent-suffix points
    to an entry (#7202)
  * Issue 7558 - During online import, the IDL should be created with in-depth
    first approach (#7559)
  * Issue 7500 - Prevent unsigned integer underflow during stalled import
  * Issue 7560 - lib389 - Add helper function for checking ASAN files
  * Issue 7539 - Server shutdown during online reindex may lead to data loss
    (#7540)
  * Issue 7549 - Substring index should validate minimum
    nsSubStrBegin/nsSubStrEnd values (#7550)
  * Issue 7440 - Substring index produces empty results and can crash when non-
    default nsSubStrBegin/nsSubStrEnd lengths are configured (#7441)
  * Issue 7267 - MDB_BAD_VALSIZE error when updating index (#7268)
  * Issue 7327 - dsctl healthcheck DSMOLE0001 inaccurate recommendations with
    multiple backends (#7328)
  * Issue 7372 - Reindex adds tombstones to ancestorid causing export failures
    (#7373)
  * Issue 7437 - LeakSanitizer: memory leaks in CoS cache error paths (#7438)
  * Issue 6922 - AddressSanitizer: leaks found by acl test suite
  * Issue 3555 - UI - Fix audit issue with npm - brace-expansion (#7556)
  * Issue 7554 - deref plugin null pointer dereference if ber_init fails
  * Issue 7519 - Ignore obsolete entrydn index when entryrdn is enabled (#7526)
  * Issue 7514 - Crash when doing moddn on very large subtree
  * Issue 7516 - dblayer_bulk_nextdata should not return an error when
    maxrecords is hit
  * Issue 7300 - RFE - Add OS-level thread names to all server threads (#7301)
  * Issue 7307 - RFE - Expose work queue and worker utilization metrics (#7308)
  * Issue 7464 - CLI - allow dsidm to work with other user types
  * Issue 7457 - Refactor memberOf perf test (#7458)
  * Issue 7452 - UI - password polices - reorganize settings
  * Issue 7431 - password policy - passwordBadWords is ignored in local policies
  * Issue 7155 - build_candidate_list - Database error 11 with range search
    (#7156)
  * Issue 7417 - UI - global password policy syntax settings missing
    passwordMaxRepeats
  * Issue 3555 - UI - Fix audit issue with npm - brace-expansion (#7411)
  * Issue 7088 - Change log level for "Can't locate CSN" error message
  * Issue 7423 - cleanup pblock after freeing pre/post entries
  * Issue 7418 - Use-after-free in deferred memberof (#7419)
  * Issue 7407 - dbscan -k option display entries that do not match the
    specified key
  * Issue 7394 - UI - Manual typing of ports can leave out digits (#7395)
  * Issue 7277 - UI - Fix Japanese translation errors errors in Cockpit UI
    (#7386)
  * Issue 7126 - WARN - keys2idl - received NULL idl from index_read_ext_allids
    (#7127)
  * Issue 7246 - correct formatting of 'Gen as CSN' in dsctl get-nsstate output
    (#7247)
  * Issue 7370 - Runtime LSan/TSan injection for pytest (#7371)
  * Issue 7378 - Make sure suffix entry always gets assigned ID 1
  * Issue 7380 - Internal op with negative wtime and large optime (#7381)
  * Issue 7362 - UI - Some FormSelect onChange parameters are reversed
  * Issue 7368 - UI - global password policy page is missing
    passwordmintokenlength
  * Issue 7366 - Memory leaks in syncrepl plugin during persistent search
    operations (#7367)
  * Issue 7271 - Add test for retrocl trimming shutdown crash (#7356)
  * Issue 3555 - UI - Fix audit issue with npm - flatted, picomatch (#7364)
  * Issue 7277 - UI - Fix Japanese translation for "Successfully updated group"
    in Cockpit UI (#7278)
  * Issue 7275 - UI - Improve password policy field validation in Cockpit UI
    (#7276)
  * Issue 7279 - UI - Fix typo in export certificate dialog (#7280)
  * Issue 6758 - Fix Enable Replication dropdown not opening (#7262)
  * Issue 6758 - Use OUIA selectors for WebUI plugin tests (#7182)
  * Issue 6758 - Fix WebUI monitoring test failure due to FormSelect component
    deprecation (#7004)
  * Issue 6758 - Fix failing webUI tests
  * Issue 1704 - DNA plugin creates invalid shared config entry with port 0
    (#7352)
  * Issue 6753 - Removing ticket 477828 test and porting to DSLdapObject (#6989)
  * Issue 7346 - DS does not handle escape char in bind user (#7347)
  * Issue 7322 - Fix cherry-pick error (reject repl agmt that points to itself)
  * Issue 7322 - Reject adding a replication agreement that points to itself
  * Issue 7342 - CI - repl config regression (#7343)
  * Issue 7291 - Crash when configuring a replica with an incorrect
    nsds5ReplicaRoot (#7292)
  * Issue - UI - Improve suffix import LDIF table
  * Issue 7325 - UI - new error parser missing import
  * Issue 7325 - UI - create an error parser for cockpit spawn errors
  * Issue 7319 - Action menu for certificates remains in empty certificate list
    (#7320)
  * Issue 7265 - CI - fix retro changelog maxage validation test
  * Issue 7093 - A password policy can be created even when an identical policy
    already exists (#7283)
  * Issue 7233 - test_produce_division_by_zero fails with IsADirectoryError in
    conftest.py (#7234)
  * Issue 7271 - Add new plugin pre-close function check to
    plugin_invoke_plugin_pb
  * Issue 7304 - retrocl should not cache DN
  * Issue 7265 - Add dse modify callback to validate retrocl trimming settings
  * Issue 7152 - ns-slapd fails to shutdown when deferred memberof update is in
    progress (#7187)
  * Issue 3555 - UI - Fix audit issue with npm - ajv, minimatch (#7298)
  * Issue 7271 - implement a pre-close plugin function
  * Issue 7295 - changelog max age validation cherry-pick error
  * Issue 7265 - changelog maxage validation is not strict enough
  * Issue 7273 - In a chaining environment binding as remote user causes an
    invalid error in the logs
  * Issue 7271 - plugins that create threads need to update active thread count
  * Issue 5853 - Update concread to 0.5.10
  * Issue 7053 - Remove memberof_del_dn_from_groups from MemberOf plugin (#7064)
  * Issue 7223 - Remove integerOrderingMatch requirement for parentid (#7264)
  * Issue 7243 - UI - fix certificate table and modal
  * Issue 7066/7052 - allow password history to be set to zero and remove
    history
  * Issue 7223 - Use lexicographical order for ancestorid (#7256)
  * Issue 7213 - (2nd) MDB_BAD_VALSIZE error while handling VLV (#7258)
  * Issue 7184 - (2nd) argparse.HelpFormatter _format_actions_usage() is
    deprecated (#7257)
  * Issue - CLI - dsctl db2index needs some hardening with MBD
  * Issue 7248 - CLI - attribute uniqueness - fix usage for exclude subtree
    option
  * Issue 7231 - Sync repl tests fail in FIPS mode due to non FIPS compliant
    crypto (#7232)
  * Issue 7224 - CI Test - Simplify test_reserve_descriptor_validation (#7225)
  * Issue 7150 - Compressed access log rotations skipped, accesslog-list out of
    sync (#7151)
  * Issue 7121 - (2nd) LeakSanitizer: various leaks during replication (#7212)
  * Issue 6947 - Fix health_system_indexes_test.py
  * Issue 7076 - Fix revert_cache() never called in modrdn (#7220)
  * Issue 7076, 6992, 6784, 6214 - Fix CI test failures (#7077)
  * Issue 7096 - (2nd) During replication online total init the function
    idl_id_is_in_idlist is not scaling with large database (#7205)
  * Issue 7223 - Add dsctl index-check command for offline index repair
  * Issue 7223 - Detect and log index ordering mismatch during backend startup
  * Issue 7223 - Add upgrade function to remove ancestorid index config entry
  * Issue 7223 - Add upgrade function to remove nsIndexIDListScanLimit from
    parentid
  * Issue 7223 - Revert index scan limits for system indexes
  * Issue 6476 - Fix build failure with GCC 15
  * Issue 6542 - RPM build errors on Fedora 42
  * Issue 7213 - MDB_BAD_VALSIZE error while handling VLV (#7214)
  * Issue 7027 - (2nd) 389-ds-base OpenScanHub Leaks Detected (#7211)
  * Issue 7184 - argparse.HelpFormatter _format_actions_usage() is deprecated
  * Issue 7189 - DSBLE0007 generates incorrect remediation commands for scan
    limits
  * Issue 7172 - (2nd) Index ordering mismatch after upgrade (#7180)
  * Issue 7172 - Index ordering mismatch after upgrade (#7173)
  * Issue - Revise paged result search locking
  * Issue 7096 - During replication online total init the function
    idl_id_is_in_idlist is not scaling with large database (#7145)
  * Issue 7049 - RetroCL plugin generates invalid LDIF

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".  
Alternatively you can run the command listed for your product:

  * Server Applications Module 15-SP7  
    zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2026-4380

## Package List:

  * Server Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64)
    * 389-ds-devel-2.8.2~git10.030ada7a6-150700.3.25.1
    * libsvrcore0-debuginfo-2.8.2~git10.030ada7a6-150700.3.25.1
    * 389-ds-debuginfo-2.8.2~git10.030ada7a6-150700.3.25.1
    * libsvrcore0-2.8.2~git10.030ada7a6-150700.3.25.1
    * lib389-2.8.2~git10.030ada7a6-150700.3.25.1
    * 389-ds-2.8.2~git10.030ada7a6-150700.3.25.1
    * 389-ds-debugsource-2.8.2~git10.030ada7a6-150700.3.25.1

## References:

  * https://www.suse.com/security/cve/CVE-2026-11770.html
  * https://www.suse.com/security/cve/CVE-2026-18355.html
  * https://www.suse.com/security/cve/CVE-2026-18453.html
  * https://www.suse.com/security/cve/CVE-2026-18922.html
  * https://www.suse.com/security/cve/CVE-2026-19843.html
  * https://www.suse.com/security/cve/CVE-2026-76560.html
  * https://bugzilla.suse.com/show_bug.cgi?id=1273133
  * https://bugzilla.suse.com/show_bug.cgi?id=1279572
  * https://bugzilla.suse.com/show_bug.cgi?id=1279864
  * https://bugzilla.suse.com/show_bug.cgi?id=1279865
  * https://bugzilla.suse.com/show_bug.cgi?id=1279866
  * https://bugzilla.suse.com/show_bug.cgi?id=1279867
  * https://jira.suse.com/browse/PED-16949

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.suse.com/pipermail/sle-security-updates/attachments/20260928/daf1032c/attachment.htm>


More information about the sle-security-updates mailing list