Security News

Cybersecurity news aggregator

🔄
CRITICAL Updates Red Hat Errata

RHSA-2026:64783: Critical: 389-ds-base security, bug fix, and enhancement update

A critical update for 389-ds-base addresses multiple vulnerabilities, including a heap buffer overflow via SASL wrapped-record length underflow (CVE-2026-18355, CVSS 7.5), a pre-authentication NULL pointer dereference (CVE-2026-18453, CVSS 7.5), and a SASL PLAIN authentication flaw allowing privilege escalation to Directory Manager (CVE-2026-18922, CVSS 9.8). The update is rated Critical by Red Hat Product Security and applies to Red Hat Enterprise Linux 9.6 Extended Update Support. Organizations should apply the referenced patch immediately.
Read Full Article →

Red Hat Product Errata RHSA-2026:64783 - Security Advisory Issued: 2026-09-08 Updated: 2026-09-08 RHSA-2026:64783 - Security Advisory Overview Updated Packages Synopsis Critical: 389-ds-base security, bug fix, and enhancement update Type/Severity Security Advisory: Critical Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for 389-ds-base is now available for Red Hat Enterprise Linux 9.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description 389 Directory Server is an LDAP version 3 (LDAPv3) compliant server. The base packages include the Lightweight Directory Access Protocol (LDAP) server and command-line utilities for server administration. Security Fix(es): 389-ds-base: 389-ds-base: heap buffer overflow via SASL wrapped-record length lower-bound underflow in sasl_io_start_packet() (CVE-2026-18355) 389-ds-base: 389-ds-base: pre-authentication NULL pointer dereference via paged results and USE_ONE_BACKEND control in op_shared_search (CVE-2026-18453) 389-ds-base: 389-ds-base: SASL PLAIN authentication allows privilege escalation to Directory Manager via stale identity in Cyrus SASL auxiliary property (CVE-2026-18922) 389-ds-base: 389-ds: anonymous LDAP client can defeat SELFDN ACI bind-rule checks via empty bind DN (CVE-2026-76560) Bug Fix(es) and Enhancement(s): lib389: set nsDS5ReplicaBindDNGroup before ensure_agreement() [rhel-9.6.z] (JIRA:RHEL-244466) fix breaks replication total init when nsDS5ReplicaBindDNGroup is set after agreement creation [rhel-9.6.z] (JIRA:RHEL-248765) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6 x86_64 Red Hat Enterprise Linux Server - AUS 9.6 x86_64 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.6 s390x Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.6 ppc64le Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.6 aarch64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.6 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.6 x86_64 Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 9.6 x86_64 Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 9.6 ppc64le Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 9.6 s390x Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 9.6 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.6 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.6 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.6 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.6 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.6 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.6 s390x Fixes BZ - 2509186 - CVE-2026-18355 389-ds-base: 389-ds-base: heap buffer overflow via SASL wrapped-record length lower-bound underflow in sasl_io_start_packet() BZ - 2509696 - CVE-2026-18453 389-ds-base: 389-ds-base: pre-authentication NULL pointer dereference via paged results and USE_ONE_BACKEND control in op_shared_search BZ - 2511388 - CVE-2026-18922 389-ds-base: 389-ds-base: SASL PLAIN authentication allows privilege escalation to Directory Manager via stale identity in Cyrus SASL auxiliary property BZ - 2519521 - CVE-2026-76560 389-ds-base: 389-ds: anonymous LDAP client can defeat SELFDN ACI bind-rule checks via empty bind DN CVEs CVE-2026-18355 CVE-2026-18453 CVE-2026-18922 CVE-2026-76560 References https://access.redhat.com/security/updates/classification/#critical Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6 SRPM 389-ds-base-2.6.1-24.el9_6.src.rpm SHA-256: 8b1bcb9a00cb86049dfcf616624850254a76af304a94124d18c76ce59912b65b x86_64 389-ds-base-2.6.1-24.el9_6.x86_64.rpm SHA-256: 4cb4baf1bbdc2d674fe758fa7d17bac51ae066f6ff8f517e8fbfbb3106b74ce5 389-ds-base-debuginfo-2.6.1-24.el9_6.x86_64.rpm SHA-256: e93b1281a046e65f55b4f7d9b2d4ced0b724071de001c49497c5a54e623317aa 389-ds-base-debugsource-2.6.1-24.el9_6.x86_64.rpm SHA-256: ce7152da85836e5a7b3542ae68c43bc4497e0a84586bd3628232167221e9b646 389-ds-base-libs-2.6.1-24.el9_6.x86_64.rpm SHA-256: 87793a0c178429fa2d484ddd559aa7960c9e4052d9f1b411833ebbd8403c147d 389-ds-base-libs-debuginfo-2.6.1-24.el9_6.x86_64.rpm SHA-256: 450db48c528737c70b017d4fcf485c60f856e73f3dd5231d6ed314fa117e7f4d 389-ds-base-snmp-2.6.1-24.el9_6.x86_64.rpm SHA-256: 6c2a0ac7f2ba0b2644d12809a3aaaa527008f7295837b6a0c56837fb238483b4 389-ds-base-snmp-debuginfo-2.6.1-24.el9_6.x86_64.rpm SHA-256: 66e9750b06d234f44faff069e57e1b0989f5db60099c069a059eb0580ba059bc python3-lib389-2.6.1-24.el9_6.noarch.rpm SHA-256: 9c29527d9cfeaedada75f53cff98c8279801d5804b2ac64889867430317a2c9e Red Hat Enterprise Linux Server - AUS 9.6 SRPM 389-ds-base-2.6.1-24.el9_6.src.rpm SHA-256: 8b1bcb9a00cb86049dfcf616624850254a76af304a94124d18c76ce59912b65b x86_64 389-ds-base-2.6.1-24.el9_6.x86_64.rpm SHA-256: 4cb4baf1bbdc2d674fe758fa7d17bac51ae066f6ff8f517e8fbfbb3106b74ce5 389-ds-base-debuginfo-2.6.1-24.el9_6.x86_64.rpm SHA-256: e93b1281a046e65f55b4f7d9b2d4ced0b724071de001c49497c5a54e623317aa 389-ds-base-debugsource-2.6.1-24.el9_6.x86_64.rpm SHA-256: ce7152da85836e5a7b3542ae68c43bc4497e0a84586bd3628232167221e9b646 389-ds-base-libs-2.6.1-24.el9_6.x86_64.rpm SHA-256: 87793a0c178429fa2d484ddd559aa7960c9e4052d9f1b411833ebbd8403c147d 389-ds-base-libs-debuginfo-2.6.1-24.el9_6.x86_64.rpm SHA-256: 450db48c528737c70b017d4fcf485c60f856e73f3dd5231d6ed314fa117e7f4d 389-ds-base-snmp-2.6.1-24.el9_6.x86_64.rpm SHA-256: 6c2a0ac7f2ba0b2644d12809a3aaaa527008f7295837b6a0c56837fb238483b4 389-ds-base-snmp-debuginfo-2.6.1-24.el9_6.x86_64.rpm SHA-256: 66e9750b06d234f44faff069e57e1b0989f5db60099c069a059eb0580ba059bc python3-lib389-2.6.1-24.el9_6.noarch.rpm SHA-256: 9c29527d9cfeaedada75f53cff98c8279801d5804b2ac64889867430317a2c9e Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.6 SRPM 389-ds-base-2.6.1-24.el9_6.src.rpm SHA-256: 8b1bcb9a00cb86049dfcf616624850254a76af304a94124d18c76ce59912b65b s390x 389-ds-base-2.6.1-24.el9_6.s390x.rpm SHA-256: d8d30e804e37b1353cb3e0ab4878ccf0d4c41ac4eb183c99b72f66e2d8dc1a26 389-ds-base-debuginfo-2.6.1-24.el9_6.s390x.rpm SHA-256: 5d99ee2b41828a85141601c1a8fef372bbf6840499bc59539ade388d4f258787 389-ds-base-debugsource-2.6.1-24.el9_6.s390x.rpm SHA-256: 41618014cc38f94ccc2cde48f13581cb622e3a3d420ac3a30b7d1d28ff28f3e1 389-ds-base-libs-2.6.1-24.el9_6.s390x.rpm SHA-256: 81eef0c9412fe406a530483f6d96fe79afc5abe05b6d9e14ae85e5be2c03c53e 389-ds-base-libs-debuginfo-2.6.1-24.el9_6.s390x.rpm SHA-256: 6fe93e2df8eef8a465921bb60ce17b69f8c30d358712b07f0d79c5d169171410 389-ds-base-snmp-2.6.1-24.el9_6.s390x.rpm SHA-256: d2fe562f827100bcf336810a8dfe0a8565230faa01075cf30d274661ad028222 389-ds-base-snmp-debuginfo-2.6.1-24.el9_6.s390x.rpm SHA-256: 2e911a17ae5ea520011b026cd8f71c60f757eed5e0ac1cb091e6429f1f7791f8 python3-lib389-2.6.1-24.el9_6.noarch.rpm SHA-256: 9c29527d9cfeaedada75f53cff98c8279801d5804b2ac64889867430317a2c9e Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.6 SRPM 389-ds-base-2.6.1-24.el9_6.src.rpm SHA-256: 8b1bcb9a00cb86049dfcf616624850254a76af304a94124d18c76ce59912b65b ppc64le 389-ds-base-2.6.1-24.el9_6.ppc64le.rpm SHA-256: 25898210c0199b556cd6a5161e7826154797d2158fd66afde6cd5e2d81e46328 389-ds-base-debuginfo-2.6.1-24.el9_6.ppc64le.rpm SHA-256: 30cd2672ceff24e40d98bcda1056f6cfaf1dae4af927c7f3ba011ec02ab0686c 389-ds-base-debugsource-2.6.1-24.el9_6.ppc64le.rpm SHA-256: 3ad29517159aec7d33dacf23aa997291fd19b3fea066fd1b086688e519a42a62 389-ds-base-libs-2.6.1-24.el9_6.ppc64le.rpm SHA-256: 8a84df251e2ed7cacbb8270734a69bc057346a7da43f31e2c906156f983cbec6 389-ds-base-libs-debuginfo-2.6.1-24.el9_6.ppc64le.rpm SHA-256: a4be97125662dd84e5566842a73ef01c1008b49071b89e08b541840729f4b579 389-ds-base-snmp-2.6.1-24.el9_6.ppc64le.rpm SHA-256: dcf516a26f8ce9eb059892a758d33155cffe3a3d196c3b12e137f52f10fc7414 389-ds-base-snmp-debuginfo-2.6.1-24.el9_6.ppc64le.rpm SHA-256: 816c7cb5d9eeb4c69d84e60a1ee38e132ace9d874cf621e9e2b3e134cf898181 python3-lib389-2.6.1-24.el9_6.noarch.rpm SHA-256: 9c29527d9cfeaedada75f53cff98c8279801d5804b2ac64889867430317a2c9e Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.6 SRPM 389-ds-base-2.6.1-24.el9_6.src.rpm SHA-256: 8b1bcb9a00cb86049dfcf616624850254a76af304a94124d18c76ce59912b65b aarch64 389-ds-base-2.6.1-24.el9_6.aarch64.rpm SHA-256: 777d922ea08e44f3cbf367b9b99649d6341ee1f6e95f29bfea77116ed371b2c9 389-ds-base-debuginfo-2.6.1-24.el9_6.aarch64.rpm SHA-256: 2981bc49464f61bde8b1857a333f8ed0722ff0bc13eab1e87b36a08654e13300 389-ds-base-debugsource-2.6.1-24.el9_6.aarch64.rpm SHA-256: 31440684d95bfb26a64b108057ceccfd6abf947754b5abd5d662b62322288ec2 389-ds-base-libs-2.6.1-24.el9_6.aarch64.rpm SHA-256: 9809d867cbaec20f77dc6f99c757cb4a3eb9bca9eecd36d38c2aac2c76e9ba48 389-ds-base-libs-debuginfo-2.6.1-24.el9_6.aarch64.rpm SHA-256: 5dd936d276d81ab54fa4663ff02b6ef74f7a834d74d175060cf05d36b27e2ad5 389-ds-base-snmp-2.6.1-24.el9_6.aarch64.rpm SHA-256: 69c746fe5868566cb49536c4b95b34440718868a4a5563885eeacd8259c976dd 389-ds-base-snmp-debuginfo-2.6.1-24.el9_6.aarch64.rpm SHA-256: 096dcb41c40136e91e5a062fbf0

Share this article