SUSE-SU-2026:4380-1: critical: Security update for 389-ds
SLE-SECURITY-UPDATES
null at suse.de
Mon Sep 28 20:33:17 UTC 2026
# Security update for 389-ds
Announcement ID: SUSE-SU-2026:4380-1
Release Date: 2026-09-28T15:18:15Z
Rating: critical
References:
* bsc#1273133
* bsc#1279572
* bsc#1279864
* bsc#1279865
* bsc#1279866
* bsc#1279867
* jsc#PED-16949
Cross-References:
* CVE-2026-11770
* CVE-2026-18355
* CVE-2026-18453
* CVE-2026-18922
* CVE-2026-19843
* CVE-2026-76560
CVSS scores:
* CVE-2026-11770 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-11770 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-18355 ( SUSE ): 7.7
CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-18355 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-18355 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-18453 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-18453 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-18453 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-18922 ( SUSE ): 9.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-18922 ( SUSE ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-18922 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-19843 ( SUSE ): 8.6
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-19843 ( SUSE ): 8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-19843 ( NVD ): 8.4 CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
* CVE-2026-76560 ( SUSE ): 8.8
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-76560 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
* CVE-2026-76560 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Affected Products:
* Server Applications Module 15-SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
An update that solves six vulnerabilities and contains one feature can now be
installed.
## Description:
This update for 389-ds fixes the following issues:
* CVE-2026-11770: pre-auth LDAP filter injection in CleanAllRUV status check
(bsc#1273133).
* CVE-2026-18355: heap buffer overflow in the SASL I/O layer allows a remote
authenticated attacker to cause a denial of service or potentially achieve
remote code execution (bsc#1279864).
* CVE-2026-18453: 389-ds-base: 389-ds-base: pre-authentication NULL pointer
dereference via paged results and USE_ONE_BACKEND control in
op_shared_search (bsc#1279572).
* CVE-2026-18922: stale identity carried in a Cyrus SASL auxiliary property
during SASL PLAIN authentication allows unauthenticated attackers to achieve
privilege escalation to Directory Manager (bsc#1279865).
* CVE-2026-19843: unescaped LDAP DN in Cockpit 389 Console LDAP editor allows
an LDAP user with delegated privileges to execute shell commands with root
privileges on the directory server host (bsc#1279866).
* CVE-2026-76560: incorrect matching in the SELFDN ACI bind-rule evaluator
allows an anonymous LDAP client to bypass access controls on directory
entries containing empty SELFDN attributes (bsc#1279867).
Changes for 389-ds:
* Update to version 2.8 LTS (jsc#PED-16949).
* Update to version 2.8.2~git10.030ada7a6:
* Issue 6596 - BUG - Compilation Regresion (#6597) (#7866)
* Issue 7627 - When it exists configured matching rule for an (#7628)
* [Backport 389-ds-base-2.8] Issue 7611 - PBKDF2 password verification should
reject invalid iteration counts (#7852)
* iadvisories/GHSA-rgxx-hcc4-x3h4 / heap-buffer-overflow in rdn_av_swap
(#7826)
* Migrate pwdchan to base64 0.23 Engine API
* Update rust-dependencies
* Issue 7823 - CI: stabilize test_controltype_expired_grace_limit (#7824)
* Issue 7815 - Support nsslapd-attribute-name-exceptions when adding entries
* Issue 7757 - stack-buffer-overflow caused by slapi_attr_init_syntax()
(#7759)
* Issue 7796 - A large received replicaID can overflow the storage buffer
(#7797)
* Issue 7041 - Add WebUI test for group member management (#7111)
* Issue 7808 - CI - harden online_import_nosync_test (#7809)
* Issue 7595 - Remove the nightly dedup gate and fix dispatched test runs
* Fix expiration time check (#7718)
* Issue 7774 - Add backport action (#7775)
* Issue 7770 - Testimony failure in test_cleanruv_extop_security.py (#7771)
* Issue 3082 - Add test389.topologies compatibility shim for backports (#7725)
* Issue 7595 - Skip redundant CI runs to relieve the Actions queue (#7751)
* Issue 7760 - CI - harden dsconf_task_test.py
* Issue 4701 - Fix UAF when excluding attrs from retro changelog (#7730)
* Issue 7723 - Range search returns an empty result when its start key is
removed (#7724)
* Issue 7735 - Heap overflow when parsing objectclass superior (#7736)
* Issue 7733 - Typo about nsuniqueid in tombstone_to_conflict (#7734)
* Issue 7284 - Creating local password policy succeeds with incorrect
passwordInHistory value (#7662)
* Issue 7284 - Automated test for creating local password policy with
incorrect passwordInHistory value (#7608)
* Issue 7284 - CI - Fix test_grace_limit_section after pwpolicy validation fix
(#7357)
* Issue 7284 - Creating local password policy succeeds with incorrect
passwordInHistory value (#7285)
* Issue 7707 - lib389: set nsDS5ReplicaBindDNGroup before ensure_agreement()
in join_supplier/hub/consumer (#7708)
* Issue 7711 - Fix typo in accountpolicy --login-history-size help text
(#7713)
* Issue 7688 - BUG - partial address leak in sso token (#7689)
* Issue 7705 - With memberOfEntryScope set, deferred memberOf skips MODIFY
operations (#7706)
* Issue 7698 - Fix silent entry loss in LMDB bulk import waiter handling
(#7699)
* Issue 7666 - Replication performance degradation during total init on high-
latency storage (#7667)
* Issue 7201 - Syscall overhead in LMDB import writer thread (#7204)
* Issue 7645 - Add runtime LeakSanitizer leak check (#7646)
* Issue 7714 - UI - sass import rules are deprecated
* Issue 7658 - Heap Buffer Overflow in sasl_io_recv() via Padded SASL UNBIND
* Issue 7710 - MemberOf deferred update - Use condvar instead of sleep loop
* Issue 7637 - fix cherry-pick error
* Issue 7637 - UI - Using Arrow Keys in New Object Wizard Resulted in DOM
Reload
* Issue 7578 - schema - attribute refcount is not maintained properly
* Issue 7605 - Harden CI test ports against ephemeral allocation (#7692)
* Issue 7528 - Retry the CI image pull instead of failing the job (#7691)
* Issue 7460 - MOD_REPLACE on groups/link attributes modifies overlap targets
(#7461)
* Issue 7670 - BDB range searches intermittently fail with err=1 under write
load (#7671)
* Issue 7108 - Fix shutdown crash in entry cache destruction (#7163)
* Issue 7200 - repl-agmt create doesn't set some parameters (#7663)
* Issue 7611 - Preserve legacy PBKDF2 hash compatibility (#7649)
* Issue 7547 - Heap buffer overflow in ldap_utf8prev()
* Issue 7611 - PBKDF2 password verification should reject invalid iteration
count (#7613)
* Issue 7558 - Total init sends the suffix entry twice (#7640)
* Issue 7635 - Integer Underflow in {SMD5} Password Comparison (#7636)
* Issue 7406 - Fix ldap-agent SNMP stats file loading (#7630)
* Issue 7621 - Stack Buffer Overflow in Password checkPrefix
* Issue 7623 - Heap Buffer Overflow in 389-ds-base Audit Log Password Masking
* Issue 7602 - CI - lib389 user compare fails due to parentid mismatch (#7603)
* Issue 7537 - CI - Fix replication log monitoring parser/timing failures
(#7592)
* Issue 7593 - Fix testimony docstring for SASL overflow test (#7606)
* Issue 7530 - CI - Stabilize DNA plugin replication tests timing out in CI
(#7572)
* Issue 7593 - Reject invalid SASL packet length values in
sasl_io_start_packet (#7594)
* Issue 3555 - UI - Fix audit issue with npm - ws, js-yaml, js-yaml, postcss,
uuid
* Issue 7541 - Add invalid ACL text header regression test (#7591)
* Issue 7541 - heap-buffer-overflows in __aclp__normalize_acltxt() (#7542)
* Issue 7576 - Fix leak of temporary attribute syntax hash tables after schema
reload
* Issue 7198 - Web console doesn't show sub-suffix when parent-suffix points
to an entry (#7202)
* Issue 7558 - During online import, the IDL should be created with in-depth
first approach (#7559)
* Issue 7500 - Prevent unsigned integer underflow during stalled import
* Issue 7560 - lib389 - Add helper function for checking ASAN files
* Issue 7539 - Server shutdown during online reindex may lead to data loss
(#7540)
* Issue 7549 - Substring index should validate minimum
nsSubStrBegin/nsSubStrEnd values (#7550)
* Issue 7440 - Substring index produces empty results and can crash when non-
default nsSubStrBegin/nsSubStrEnd lengths are configured (#7441)
* Issue 7267 - MDB_BAD_VALSIZE error when updating index (#7268)
* Issue 7327 - dsctl healthcheck DSMOLE0001 inaccurate recommendations with
multiple backends (#7328)
* Issue 7372 - Reindex adds tombstones to ancestorid causing export failures
(#7373)
* Issue 7437 - LeakSanitizer: memory leaks in CoS cache error paths (#7438)
* Issue 6922 - AddressSanitizer: leaks found by acl test suite
* Issue 3555 - UI - Fix audit issue with npm - brace-expansion (#7556)
* Issue 7554 - deref plugin null pointer dereference if ber_init fails
* Issue 7519 - Ignore obsolete entrydn index when entryrdn is enabled (#7526)
* Issue 7514 - Crash when doing moddn on very large subtree
* Issue 7516 - dblayer_bulk_nextdata should not return an error when
maxrecords is hit
* Issue 7300 - RFE - Add OS-level thread names to all server threads (#7301)
* Issue 7307 - RFE - Expose work queue and worker utilization metrics (#7308)
* Issue 7464 - CLI - allow dsidm to work with other user types
* Issue 7457 - Refactor memberOf perf test (#7458)
* Issue 7452 - UI - password polices - reorganize settings
* Issue 7431 - password policy - passwordBadWords is ignored in local policies
* Issue 7155 - build_candidate_list - Database error 11 with range search
(#7156)
* Issue 7417 - UI - global password policy syntax settings missing
passwordMaxRepeats
* Issue 3555 - UI - Fix audit issue with npm - brace-expansion (#7411)
* Issue 7088 - Change log level for "Can't locate CSN" error message
* Issue 7423 - cleanup pblock after freeing pre/post entries
* Issue 7418 - Use-after-free in deferred memberof (#7419)
* Issue 7407 - dbscan -k option display entries that do not match the
specified key
* Issue 7394 - UI - Manual typing of ports can leave out digits (#7395)
* Issue 7277 - UI - Fix Japanese translation errors errors in Cockpit UI
(#7386)
* Issue 7126 - WARN - keys2idl - received NULL idl from index_read_ext_allids
(#7127)
* Issue 7246 - correct formatting of 'Gen as CSN' in dsctl get-nsstate output
(#7247)
* Issue 7370 - Runtime LSan/TSan injection for pytest (#7371)
* Issue 7378 - Make sure suffix entry always gets assigned ID 1
* Issue 7380 - Internal op with negative wtime and large optime (#7381)
* Issue 7362 - UI - Some FormSelect onChange parameters are reversed
* Issue 7368 - UI - global password policy page is missing
passwordmintokenlength
* Issue 7366 - Memory leaks in syncrepl plugin during persistent search
operations (#7367)
* Issue 7271 - Add test for retrocl trimming shutdown crash (#7356)
* Issue 3555 - UI - Fix audit issue with npm - flatted, picomatch (#7364)
* Issue 7277 - UI - Fix Japanese translation for "Successfully updated group"
in Cockpit UI (#7278)
* Issue 7275 - UI - Improve password policy field validation in Cockpit UI
(#7276)
* Issue 7279 - UI - Fix typo in export certificate dialog (#7280)
* Issue 6758 - Fix Enable Replication dropdown not opening (#7262)
* Issue 6758 - Use OUIA selectors for WebUI plugin tests (#7182)
* Issue 6758 - Fix WebUI monitoring test failure due to FormSelect component
deprecation (#7004)
* Issue 6758 - Fix failing webUI tests
* Issue 1704 - DNA plugin creates invalid shared config entry with port 0
(#7352)
* Issue 6753 - Removing ticket 477828 test and porting to DSLdapObject (#6989)
* Issue 7346 - DS does not handle escape char in bind user (#7347)
* Issue 7322 - Fix cherry-pick error (reject repl agmt that points to itself)
* Issue 7322 - Reject adding a replication agreement that points to itself
* Issue 7342 - CI - repl config regression (#7343)
* Issue 7291 - Crash when configuring a replica with an incorrect
nsds5ReplicaRoot (#7292)
* Issue - UI - Improve suffix import LDIF table
* Issue 7325 - UI - new error parser missing import
* Issue 7325 - UI - create an error parser for cockpit spawn errors
* Issue 7319 - Action menu for certificates remains in empty certificate list
(#7320)
* Issue 7265 - CI - fix retro changelog maxage validation test
* Issue 7093 - A password policy can be created even when an identical policy
already exists (#7283)
* Issue 7233 - test_produce_division_by_zero fails with IsADirectoryError in
conftest.py (#7234)
* Issue 7271 - Add new plugin pre-close function check to
plugin_invoke_plugin_pb
* Issue 7304 - retrocl should not cache DN
* Issue 7265 - Add dse modify callback to validate retrocl trimming settings
* Issue 7152 - ns-slapd fails to shutdown when deferred memberof update is in
progress (#7187)
* Issue 3555 - UI - Fix audit issue with npm - ajv, minimatch (#7298)
* Issue 7271 - implement a pre-close plugin function
* Issue 7295 - changelog max age validation cherry-pick error
* Issue 7265 - changelog maxage validation is not strict enough
* Issue 7273 - In a chaining environment binding as remote user causes an
invalid error in the logs
* Issue 7271 - plugins that create threads need to update active thread count
* Issue 5853 - Update concread to 0.5.10
* Issue 7053 - Remove memberof_del_dn_from_groups from MemberOf plugin (#7064)
* Issue 7223 - Remove integerOrderingMatch requirement for parentid (#7264)
* Issue 7243 - UI - fix certificate table and modal
* Issue 7066/7052 - allow password history to be set to zero and remove
history
* Issue 7223 - Use lexicographical order for ancestorid (#7256)
* Issue 7213 - (2nd) MDB_BAD_VALSIZE error while handling VLV (#7258)
* Issue 7184 - (2nd) argparse.HelpFormatter _format_actions_usage() is
deprecated (#7257)
* Issue - CLI - dsctl db2index needs some hardening with MBD
* Issue 7248 - CLI - attribute uniqueness - fix usage for exclude subtree
option
* Issue 7231 - Sync repl tests fail in FIPS mode due to non FIPS compliant
crypto (#7232)
* Issue 7224 - CI Test - Simplify test_reserve_descriptor_validation (#7225)
* Issue 7150 - Compressed access log rotations skipped, accesslog-list out of
sync (#7151)
* Issue 7121 - (2nd) LeakSanitizer: various leaks during replication (#7212)
* Issue 6947 - Fix health_system_indexes_test.py
* Issue 7076 - Fix revert_cache() never called in modrdn (#7220)
* Issue 7076, 6992, 6784, 6214 - Fix CI test failures (#7077)
* Issue 7096 - (2nd) During replication online total init the function
idl_id_is_in_idlist is not scaling with large database (#7205)
* Issue 7223 - Add dsctl index-check command for offline index repair
* Issue 7223 - Detect and log index ordering mismatch during backend startup
* Issue 7223 - Add upgrade function to remove ancestorid index config entry
* Issue 7223 - Add upgrade function to remove nsIndexIDListScanLimit from
parentid
* Issue 7223 - Revert index scan limits for system indexes
* Issue 6476 - Fix build failure with GCC 15
* Issue 6542 - RPM build errors on Fedora 42
* Issue 7213 - MDB_BAD_VALSIZE error while handling VLV (#7214)
* Issue 7027 - (2nd) 389-ds-base OpenScanHub Leaks Detected (#7211)
* Issue 7184 - argparse.HelpFormatter _format_actions_usage() is deprecated
* Issue 7189 - DSBLE0007 generates incorrect remediation commands for scan
limits
* Issue 7172 - (2nd) Index ordering mismatch after upgrade (#7180)
* Issue 7172 - Index ordering mismatch after upgrade (#7173)
* Issue - Revise paged result search locking
* Issue 7096 - During replication online total init the function
idl_id_is_in_idlist is not scaling with large database (#7145)
* Issue 7049 - RetroCL plugin generates invalid LDIF
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* Server Applications Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2026-4380
## Package List:
* Server Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* 389-ds-devel-2.8.2~git10.030ada7a6-150700.3.25.1
* libsvrcore0-debuginfo-2.8.2~git10.030ada7a6-150700.3.25.1
* 389-ds-debuginfo-2.8.2~git10.030ada7a6-150700.3.25.1
* libsvrcore0-2.8.2~git10.030ada7a6-150700.3.25.1
* lib389-2.8.2~git10.030ada7a6-150700.3.25.1
* 389-ds-2.8.2~git10.030ada7a6-150700.3.25.1
* 389-ds-debugsource-2.8.2~git10.030ada7a6-150700.3.25.1
## References:
* https://www.suse.com/security/cve/CVE-2026-11770.html
* https://www.suse.com/security/cve/CVE-2026-18355.html
* https://www.suse.com/security/cve/CVE-2026-18453.html
* https://www.suse.com/security/cve/CVE-2026-18922.html
* https://www.suse.com/security/cve/CVE-2026-19843.html
* https://www.suse.com/security/cve/CVE-2026-76560.html
* https://bugzilla.suse.com/show_bug.cgi?id=1273133
* https://bugzilla.suse.com/show_bug.cgi?id=1279572
* https://bugzilla.suse.com/show_bug.cgi?id=1279864
* https://bugzilla.suse.com/show_bug.cgi?id=1279865
* https://bugzilla.suse.com/show_bug.cgi?id=1279866
* https://bugzilla.suse.com/show_bug.cgi?id=1279867
* https://jira.suse.com/browse/PED-16949
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.suse.com/pipermail/sle-security-updates/attachments/20260928/daf1032c/attachment.htm>
More information about the sle-security-updates
mailing list