- What: Security update for Red Hat Directory Server
- Impact: Addresses vulnerabilities in the LDAP server
Red Hat Product Errata RHSA-2026:56048 - Security Advisory Issued: 2026-08-18 Updated: 2026-08-18 RHSA-2026:56048 - Security Advisory Overview Updated Packages Synopsis Important: redhat-ds:12 security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for the redhat-ds:12 module is now available for Red Hat Directory Server 12.2 E4S for RHEL 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Red Hat Directory Server is an LDAPv3-compliant directory server. The suite of packages includes the Lightweight Directory Access Protocol (LDAP) server, as well as command-line utilities and Web UI packages for server administration. Security Fix(es): 389-ds-base: 389-ds-base: pre-auth LDAP filter injection in CleanAllRUV status check (CVE-2026-11770) 389-ds-base: 389-ds-base: NULL pointer dereference in deref control plugin BER parser (CVE-2026-11788) 389-ds-base: 389-ds-base: pre-authentication stack buffer overflow in get_ruvelement_from_berval() via unbounded replica ID parsing (CVE-2026-15722) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Directory Server - 4 years of updates 12 for RHEL 9.2 x86_64 Fixes BZ - 2484802 - CVE-2026-11770 389-ds-base: 389-ds-base: pre-auth LDAP filter injection in CleanAllRUV status check BZ - 2485423 - CVE-2026-11788 389-ds-base: 389-ds-base: NULL pointer dereference in deref control plugin BER parser BZ - 2499961 - CVE-2026-15722 389-ds-base: 389-ds-base: pre-authentication stack buffer overflow in get_ruvelement_from_berval() via unbounded replica ID parsing CVEs CVE-2026-11770 CVE-2026-11788 CVE-2026-15722 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Directory Server - 4 years of updates 12 for RHEL 9.2 SRPM 389-ds-base-2.2.7-17.module+el9dsrv+24586+9fc9d4dc.src.rpm SHA-256: be340c4d8465e700bea74deba2ecdbf70c56e0d1846ddd0df3c129df5be74ea7 x86_64 389-ds-base-2.2.7-17.module+el9dsrv+24586+9fc9d4dc.x86_64.rpm SHA-256: 4b413e2b75ec8cdcccb537bd55a272e43394466ff820d0982d4ca17f0b57e21a 389-ds-base-debuginfo-2.2.7-17.module+el9dsrv+24586+9fc9d4dc.x86_64.rpm SHA-256: b795b43adfdf86ef89528eedf7d6cda33f3bd8900779731ce35f8e12a68be58a 389-ds-base-debugsource-2.2.7-17.module+el9dsrv+24586+9fc9d4dc.x86_64.rpm SHA-256: 2bc4487c1a1dbe9ac12b24c96c9e60aeae69ed8326d147151812cdca4670e1e8 389-ds-base-devel-2.2.7-17.module+el9dsrv+24586+9fc9d4dc.x86_64.rpm SHA-256: 824cb413d2680171395a348335084113412937e66ca824c4ca5ac3de2131d159 389-ds-base-libs-2.2.7-17.module+el9dsrv+24586+9fc9d4dc.x86_64.rpm SHA-256: f33b67ca5fffc79879f3a5f2fe083c607ee7c65d36874d95ccf7ae060de57245 389-ds-base-libs-debuginfo-2.2.7-17.module+el9dsrv+24586+9fc9d4dc.x86_64.rpm SHA-256: bf81bf8380c2ac4b5f0d0572cd88ab884f63f137a56e50a86d0af57878b2d904 389-ds-base-snmp-2.2.7-17.module+el9dsrv+24586+9fc9d4dc.x86_64.rpm SHA-256: 6ca483aadba14892164a8741db7ddcc6194906ccded06557bdbd50184c642bfe 389-ds-base-snmp-debuginfo-2.2.7-17.module+el9dsrv+24586+9fc9d4dc.x86_64.rpm SHA-256: 8e6cd735f5489dea658504a14883ce8890799e3bf66f2bbfca8d5c47e69b7aab cockpit-389-ds-2.2.7-17.module+el9dsrv+24586+9fc9d4dc.noarch.rpm SHA-256: 9476baa660a0ae091371d8503141eb74e6ff17741ff08b8d6f4132ec1ee476d9 python3-lib389-2.2.7-17.module+el9dsrv+24586+9fc9d4dc.noarch.rpm SHA-256: 3a0ef345f60291451798a4a45346e6091495a65647addf854493c062cceb6d8b The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .