SUSE-SU-2026:23916-1: critical: Security update for 389-ds

SLE-UPDATES null at suse.de
Tue Sep 29 20:33:22 UTC 2026


# Security update for 389-ds

Announcement ID: SUSE-SU-2026:23916-1  
Release Date: 2026-09-24T09:28:31Z  
Rating: critical  
References:

  * bsc#1273133
  * bsc#1279572
  * bsc#1279864
  * bsc#1279865
  * bsc#1279866
  * bsc#1279867

  
Cross-References:

  * CVE-2026-11770
  * CVE-2026-18355
  * CVE-2026-18453
  * CVE-2026-18922
  * CVE-2026-19843
  * CVE-2026-76560

  
CVSS scores:

  * CVE-2026-11770 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  * CVE-2026-11770 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  * CVE-2026-18355 ( SUSE ):  7.7
    CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-18355 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-18355 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-18453 ( SUSE ):  6.9
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
  * CVE-2026-18453 ( SUSE ):  5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
  * CVE-2026-18453 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-18922 ( SUSE ):  9.3
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-18922 ( SUSE ):  9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-18922 ( NVD ):  9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-19843 ( SUSE ):  8.6
    CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-19843 ( SUSE ):  8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
  * CVE-2026-19843 ( NVD ):  8.4 CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
  * CVE-2026-76560 ( SUSE ):  8.8
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-76560 ( SUSE ):  8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
  * CVE-2026-76560 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

  
Affected Products:

  * SUSE Linux Enterprise Server 16.0
  * SUSE Linux Enterprise Server for SAP applications 16.0

  
  
An update that solves six vulnerabilities can now be installed.

## Description:

This update for 389-ds fixes the following issues:

  * CVE-2026-11770: pre-auth LDAP filter injection in CleanAllRUV status check
    (bsc#1273133).
  * CVE-2026-18355: heap buffer overflow in the SASL I/O layer allows a remote
    authenticated attacker to cause a denial of service or potentially achieve
    remote code execution (bsc#1279864).
  * CVE-2026-18453: 389-ds-base: 389-ds-base: pre-authentication NULL pointer
    dereference via paged results and USE_ONE_BACKEND control in
    op_shared_search (bsc#1279572).
  * CVE-2026-18922: stale identity carried in a Cyrus SASL auxiliary property
    during SASL PLAIN authentication allows unauthenticated attackers to achieve
    privilege escalation to Directory Manager (bsc#1279865).
  * CVE-2026-19843: unescaped LDAP DN in Cockpit 389 Console LDAP editor allows
    an LDAP user with delegated privileges to execute shell commands with root
    privileges on the directory server host (bsc#1279866).
  * CVE-2026-76560: incorrect matching in the SELFDN ACI bind-rule evaluator
    allows an anonymous LDAP client to bypass access controls on directory
    entries containing empty SELFDN attributes (bsc#1279867).

Changes for 389-ds:

  * Update to version 3.0.7~git2.2846d5288:

  * Issue 7757 - stack-buffer-overflow caused by slapi_attr_init_syntax()
    (#7759)

  * Issue 7796 - A large received replicaID can overflow the storage buffer
    (#7797)
  * Issue 7041 - Add WebUI test for group member management (#7111)
  * Issue 7808 - CI - harden online_import_nosync_test (#7809)
  * Issue 7611 - PBKDF2 password verification should reject invalid iteration
    counts (#7632) (#7812)
  * [Backport 389-ds-base-3.0] Update rust-dependencies (#7799)
  * Issue 7595 - Remove the nightly dedup gate and fix dispatched test runs
  * Fix expiration time check (#7718)
  * Issue 7774 - Add backport action (#7775)
  * Issue 7770 - Testimony failure in test_cleanruv_extop_security.py (#7771)
  * Issue 3082 - Add test389.topologies compatibility shim for backports (#7725)
  * Issue 7595 - Skip redundant CI runs to relieve the Actions queue (#7749)
  * Issue 7760 - CI - harden dsconf_task_test.py
  * Issue 4701 - Fix UAF when excluding attrs from retro changelog (#7730)
  * Issue 7723 - Range search returns an empty result when its start key is
    removed (#7724)
  * Issue 7639 - Move log compression outside of global write lock
  * Issue 7631 - Don't install bpftrace by default (#7726)
  * Issue 7735 - Heap overflow when parsing objectclass superior (#7736)
  * Issue 7733 - Typo about nsuniqueid in tombstone_to_conflict (#7734)
  * Issue 7707 - lib389: set nsDS5ReplicaBindDNGroup before ensure_agreement()
    in join_supplier/hub/consumer (#7708)

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".  
Alternatively you can run the command listed for your product:

  * SUSE Linux Enterprise Server for SAP applications 16.0  
    zypper in -t patch SUSE-SLES-16.0-1759

  * SUSE Linux Enterprise Server 16.0  
    zypper in -t patch SUSE-SLES-16.0-1759

## Package List:

  * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64)
    * libsvrcore0-debuginfo-3.0.7~git2.2846d5288-160000.1.1
    * 389-ds-debuginfo-3.0.7~git2.2846d5288-160000.1.1
    * 389-ds-snmp-3.0.7~git2.2846d5288-160000.1.1
    * 389-ds-3.0.7~git2.2846d5288-160000.1.1
    * 389-ds-snmp-debuginfo-3.0.7~git2.2846d5288-160000.1.1
    * lib389-3.0.7~git2.2846d5288-160000.1.1
    * 389-ds-devel-3.0.7~git2.2846d5288-160000.1.1
    * libsvrcore0-3.0.7~git2.2846d5288-160000.1.1
    * 389-ds-debugsource-3.0.7~git2.2846d5288-160000.1.1
  * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64)
    * libsvrcore0-debuginfo-3.0.7~git2.2846d5288-160000.1.1
    * 389-ds-debuginfo-3.0.7~git2.2846d5288-160000.1.1
    * 389-ds-snmp-3.0.7~git2.2846d5288-160000.1.1
    * 389-ds-3.0.7~git2.2846d5288-160000.1.1
    * 389-ds-snmp-debuginfo-3.0.7~git2.2846d5288-160000.1.1
    * lib389-3.0.7~git2.2846d5288-160000.1.1
    * 389-ds-devel-3.0.7~git2.2846d5288-160000.1.1
    * libsvrcore0-3.0.7~git2.2846d5288-160000.1.1
    * 389-ds-debugsource-3.0.7~git2.2846d5288-160000.1.1

## References:

  * https://www.suse.com/security/cve/CVE-2026-11770.html
  * https://www.suse.com/security/cve/CVE-2026-18355.html
  * https://www.suse.com/security/cve/CVE-2026-18453.html
  * https://www.suse.com/security/cve/CVE-2026-18922.html
  * https://www.suse.com/security/cve/CVE-2026-19843.html
  * https://www.suse.com/security/cve/CVE-2026-76560.html
  * https://bugzilla.suse.com/show_bug.cgi?id=1273133
  * https://bugzilla.suse.com/show_bug.cgi?id=1279572
  * https://bugzilla.suse.com/show_bug.cgi?id=1279864
  * https://bugzilla.suse.com/show_bug.cgi?id=1279865
  * https://bugzilla.suse.com/show_bug.cgi?id=1279866
  * https://bugzilla.suse.com/show_bug.cgi?id=1279867

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.suse.com/pipermail/sle-updates/attachments/20260929/308d0bd9/attachment.htm>


More information about the sle-updates mailing list