- What: Critical security update for 389-ds-base in Red Hat Enterprise Linux 7
- Impact: Systems using the LDAP server may be affected
Red Hat Product Errata RHSA-2026:64771 - Security Advisory Issued: 2026-09-08 Updated: 2026-09-08 RHSA-2026:64771 - Security Advisory Overview Updated Packages Synopsis Critical: 389-ds-base security, bug fix, and enhancement update Type/Severity Security Advisory: Critical Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for 389-ds-base is now available for Red Hat Enterprise Linux 7 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description 389 Directory Server is an LDAP version 3 (LDAPv3) compliant server. The base packages include the Lightweight Directory Access Protocol (LDAP) server and command-line utilities for server administration. Security Fix(es): 389-ds-base: 389-ds-base: heap buffer overflow via SASL wrapped-record length lower-bound underflow in sasl_io_start_packet() (CVE-2026-18355) 389-ds-base: 389-ds-base: pre-authentication NULL pointer dereference via paged results and USE_ONE_BACKEND control in op_shared_search (CVE-2026-18453) 389-ds-base: 389-ds-base: SASL PLAIN authentication allows privilege escalation to Directory Manager via stale identity in Cyrus SASL auxiliary property (CVE-2026-18922) 389-ds-base: 389-ds: anonymous LDAP client can defeat SELFDN ACI bind-rule checks via empty bind DN (CVE-2026-76560) Bug Fix(es) and Enhancement(s): fix breaks replication total init when nsDS5ReplicaBindDNGroup is set after agreement creation [rhel-7.9.z] (JIRA:RHEL-248758) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux Server - Extended Life Cycle Support 7 x86_64 Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7 s390x Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7 ppc64 Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7 ppc64le Fixes BZ - 2509186 - CVE-2026-18355 389-ds-base: 389-ds-base: heap buffer overflow via SASL wrapped-record length lower-bound underflow in sasl_io_start_packet() BZ - 2509696 - CVE-2026-18453 389-ds-base: 389-ds-base: pre-authentication NULL pointer dereference via paged results and USE_ONE_BACKEND control in op_shared_search BZ - 2511388 - CVE-2026-18922 389-ds-base: 389-ds-base: SASL PLAIN authentication allows privilege escalation to Directory Manager via stale identity in Cyrus SASL auxiliary property BZ - 2519521 - CVE-2026-76560 389-ds-base: 389-ds: anonymous LDAP client can defeat SELFDN ACI bind-rule checks via empty bind DN CVEs CVE-2026-18355 CVE-2026-18453 CVE-2026-18922 CVE-2026-76560 References https://access.redhat.com/security/updates/classification/#critical Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux Server - Extended Life Cycle Support 7 SRPM 389-ds-base-1.3.11.1-15.el7_9.src.rpm SHA-256: f466c04abe9e944d14116cb1a1f08fc06bb722f71ba0160f5eacc52839e17b19 x86_64 389-ds-base-1.3.11.1-15.el7_9.x86_64.rpm SHA-256: 6c57c4a1e65c15e63457aee4f73852d97618489dd6411119c467412b4cabbba6 389-ds-base-debuginfo-1.3.11.1-15.el7_9.x86_64.rpm SHA-256: 94d6cbe9ee1ee07f7f8a15ea06873961366a28d3a1ef50dcee4c6d6fe1993992 389-ds-base-debuginfo-1.3.11.1-15.el7_9.x86_64.rpm SHA-256: 94d6cbe9ee1ee07f7f8a15ea06873961366a28d3a1ef50dcee4c6d6fe1993992 389-ds-base-devel-1.3.11.1-15.el7_9.x86_64.rpm SHA-256: 65ff872ae837d058a3b5b5f51bf5b89df1255328e3d9ad3fccfebb23aa47c5b1 389-ds-base-libs-1.3.11.1-15.el7_9.x86_64.rpm SHA-256: 4ac49068f9cc1c59027417da0e02e421e5a7a846f39d2cf9b7df00d8af8bd373 389-ds-base-snmp-1.3.11.1-15.el7_9.x86_64.rpm SHA-256: 9ab91785c7a2779aff68e79e9e0fb9e90b0720eb4814210b24847721cb0fb334 Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7 SRPM 389-ds-base-1.3.11.1-15.el7_9.src.rpm SHA-256: f466c04abe9e944d14116cb1a1f08fc06bb722f71ba0160f5eacc52839e17b19 s390x 389-ds-base-1.3.11.1-15.el7_9.s390x.rpm SHA-256: ac0f6b1b4480531ab58442af73687e1452abacf7f9e7a5f8f29b1a67d8873752 389-ds-base-debuginfo-1.3.11.1-15.el7_9.s390x.rpm SHA-256: 0888886e9dee0b464eb896a547664dbb4d292eab80a7540c47be457c46122daf 389-ds-base-devel-1.3.11.1-15.el7_9.s390x.rpm SHA-256: d8542cbbf4e1e9bbe92b41ad529d850f411d52035e94f4e7338bb0b83497fd90 389-ds-base-libs-1.3.11.1-15.el7_9.s390x.rpm SHA-256: 0b0d8e805e84952cdb9fa18ce036655eb4a6a812df69979d57053d6b8a917562 389-ds-base-snmp-1.3.11.1-15.el7_9.s390x.rpm SHA-256: 36781bf2761fa7d9c9a435b018d0b36d63a7be2a5d99ffabc0e92ac8d0d468a9 Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7 SRPM 389-ds-base-1.3.11.1-15.el7_9.src.rpm SHA-256: f466c04abe9e944d14116cb1a1f08fc06bb722f71ba0160f5eacc52839e17b19 ppc64 389-ds-base-1.3.11.1-15.el7_9.ppc64.rpm SHA-256: ff5c72a5effe2b033e98a923f50af1c1f3ed996a34c16f433fffeecb38e84846 389-ds-base-debuginfo-1.3.11.1-15.el7_9.ppc64.rpm SHA-256: 5c6cd1b664eb082d1bf21401a1e17231fce847691e1ebb45f43d09a33441e2bf 389-ds-base-devel-1.3.11.1-15.el7_9.ppc64.rpm SHA-256: 1fca98a2acf5ca92ce16c2c9b5ff5e57068cb98c767eabfefeb075321d65b207 389-ds-base-libs-1.3.11.1-15.el7_9.ppc64.rpm SHA-256: 958abe7253700237169ebd136430a3803bfe6127001e2684f905c47be11261bd 389-ds-base-snmp-1.3.11.1-15.el7_9.ppc64.rpm SHA-256: fe3b8ee9d20a69c0697e884aaa533a84ebd439cc730486d54eaac6aa933b8427 Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7 SRPM 389-ds-base-1.3.11.1-15.el7_9.src.rpm SHA-256: f466c04abe9e944d14116cb1a1f08fc06bb722f71ba0160f5eacc52839e17b19 ppc64le 389-ds-base-1.3.11.1-15.el7_9.ppc64le.rpm SHA-256: 078d12f156ebe59fd03d73a438506abf33ed8b6a1af304f0464aa110098d6dab 389-ds-base-debuginfo-1.3.11.1-15.el7_9.ppc64le.rpm SHA-256: d83c850e4a55194c44db4382f1124e78c0737c0aa6f01b0afc1fcb524262248d 389-ds-base-debuginfo-1.3.11.1-15.el7_9.ppc64le.rpm SHA-256: d83c850e4a55194c44db4382f1124e78c0737c0aa6f01b0afc1fcb524262248d 389-ds-base-devel-1.3.11.1-15.el7_9.ppc64le.rpm SHA-256: d40842b9b3feb324681150c6ea53167de55759f6d4a950955666f8c23ff0cacf 389-ds-base-libs-1.3.11.1-15.el7_9.ppc64le.rpm SHA-256: 4fec582d19ce9cbceae3df77f870d7c67c3f69ec5d426c00918ecb05fa0d04b3 389-ds-base-snmp-1.3.11.1-15.el7_9.ppc64le.rpm SHA-256: eee8764f3c440810bb55f25bd7d20b5f50808892594fa7f7ab5bbd0752938e39 The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .