SUSE-SU-2026:23916-1: critical: Security update for 389-ds
SLE-SECURITY-UPDATES
null at suse.de
Tue Sep 29 20:33:39 UTC 2026
# Security update for 389-ds
Announcement ID: SUSE-SU-2026:23916-1
Release Date: 2026-09-24T09:28:31Z
Rating: critical
References:
* bsc#1273133
* bsc#1279572
* bsc#1279864
* bsc#1279865
* bsc#1279866
* bsc#1279867
Cross-References:
* CVE-2026-11770
* CVE-2026-18355
* CVE-2026-18453
* CVE-2026-18922
* CVE-2026-19843
* CVE-2026-76560
CVSS scores:
* CVE-2026-11770 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-11770 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-18355 ( SUSE ): 7.7
CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-18355 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-18355 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-18453 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-18453 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-18453 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-18922 ( SUSE ): 9.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-18922 ( SUSE ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-18922 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-19843 ( SUSE ): 8.6
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-19843 ( SUSE ): 8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
* CVE-2026-19843 ( NVD ): 8.4 CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
* CVE-2026-76560 ( SUSE ): 8.8
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-76560 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
* CVE-2026-76560 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Affected Products:
* SUSE Linux Enterprise Server 16.0
* SUSE Linux Enterprise Server for SAP applications 16.0
An update that solves six vulnerabilities can now be installed.
## Description:
This update for 389-ds fixes the following issues:
* CVE-2026-11770: pre-auth LDAP filter injection in CleanAllRUV status check
(bsc#1273133).
* CVE-2026-18355: heap buffer overflow in the SASL I/O layer allows a remote
authenticated attacker to cause a denial of service or potentially achieve
remote code execution (bsc#1279864).
* CVE-2026-18453: 389-ds-base: 389-ds-base: pre-authentication NULL pointer
dereference via paged results and USE_ONE_BACKEND control in
op_shared_search (bsc#1279572).
* CVE-2026-18922: stale identity carried in a Cyrus SASL auxiliary property
during SASL PLAIN authentication allows unauthenticated attackers to achieve
privilege escalation to Directory Manager (bsc#1279865).
* CVE-2026-19843: unescaped LDAP DN in Cockpit 389 Console LDAP editor allows
an LDAP user with delegated privileges to execute shell commands with root
privileges on the directory server host (bsc#1279866).
* CVE-2026-76560: incorrect matching in the SELFDN ACI bind-rule evaluator
allows an anonymous LDAP client to bypass access controls on directory
entries containing empty SELFDN attributes (bsc#1279867).
Changes for 389-ds:
* Update to version 3.0.7~git2.2846d5288:
* Issue 7757 - stack-buffer-overflow caused by slapi_attr_init_syntax()
(#7759)
* Issue 7796 - A large received replicaID can overflow the storage buffer
(#7797)
* Issue 7041 - Add WebUI test for group member management (#7111)
* Issue 7808 - CI - harden online_import_nosync_test (#7809)
* Issue 7611 - PBKDF2 password verification should reject invalid iteration
counts (#7632) (#7812)
* [Backport 389-ds-base-3.0] Update rust-dependencies (#7799)
* Issue 7595 - Remove the nightly dedup gate and fix dispatched test runs
* Fix expiration time check (#7718)
* Issue 7774 - Add backport action (#7775)
* Issue 7770 - Testimony failure in test_cleanruv_extop_security.py (#7771)
* Issue 3082 - Add test389.topologies compatibility shim for backports (#7725)
* Issue 7595 - Skip redundant CI runs to relieve the Actions queue (#7749)
* Issue 7760 - CI - harden dsconf_task_test.py
* Issue 4701 - Fix UAF when excluding attrs from retro changelog (#7730)
* Issue 7723 - Range search returns an empty result when its start key is
removed (#7724)
* Issue 7639 - Move log compression outside of global write lock
* Issue 7631 - Don't install bpftrace by default (#7726)
* Issue 7735 - Heap overflow when parsing objectclass superior (#7736)
* Issue 7733 - Typo about nsuniqueid in tombstone_to_conflict (#7734)
* Issue 7707 - lib389: set nsDS5ReplicaBindDNGroup before ensure_agreement()
in join_supplier/hub/consumer (#7708)
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Server for SAP applications 16.0
zypper in -t patch SUSE-SLES-16.0-1759
* SUSE Linux Enterprise Server 16.0
zypper in -t patch SUSE-SLES-16.0-1759
## Package List:
* SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64)
* libsvrcore0-debuginfo-3.0.7~git2.2846d5288-160000.1.1
* 389-ds-debuginfo-3.0.7~git2.2846d5288-160000.1.1
* 389-ds-snmp-3.0.7~git2.2846d5288-160000.1.1
* 389-ds-3.0.7~git2.2846d5288-160000.1.1
* 389-ds-snmp-debuginfo-3.0.7~git2.2846d5288-160000.1.1
* lib389-3.0.7~git2.2846d5288-160000.1.1
* 389-ds-devel-3.0.7~git2.2846d5288-160000.1.1
* libsvrcore0-3.0.7~git2.2846d5288-160000.1.1
* 389-ds-debugsource-3.0.7~git2.2846d5288-160000.1.1
* SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64)
* libsvrcore0-debuginfo-3.0.7~git2.2846d5288-160000.1.1
* 389-ds-debuginfo-3.0.7~git2.2846d5288-160000.1.1
* 389-ds-snmp-3.0.7~git2.2846d5288-160000.1.1
* 389-ds-3.0.7~git2.2846d5288-160000.1.1
* 389-ds-snmp-debuginfo-3.0.7~git2.2846d5288-160000.1.1
* lib389-3.0.7~git2.2846d5288-160000.1.1
* 389-ds-devel-3.0.7~git2.2846d5288-160000.1.1
* libsvrcore0-3.0.7~git2.2846d5288-160000.1.1
* 389-ds-debugsource-3.0.7~git2.2846d5288-160000.1.1
## References:
* https://www.suse.com/security/cve/CVE-2026-11770.html
* https://www.suse.com/security/cve/CVE-2026-18355.html
* https://www.suse.com/security/cve/CVE-2026-18453.html
* https://www.suse.com/security/cve/CVE-2026-18922.html
* https://www.suse.com/security/cve/CVE-2026-19843.html
* https://www.suse.com/security/cve/CVE-2026-76560.html
* https://bugzilla.suse.com/show_bug.cgi?id=1273133
* https://bugzilla.suse.com/show_bug.cgi?id=1279572
* https://bugzilla.suse.com/show_bug.cgi?id=1279864
* https://bugzilla.suse.com/show_bug.cgi?id=1279865
* https://bugzilla.suse.com/show_bug.cgi?id=1279866
* https://bugzilla.suse.com/show_bug.cgi?id=1279867
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.suse.com/pipermail/sle-security-updates/attachments/20260929/0c3b7f48/attachment.htm>
More information about the sle-security-updates
mailing list