Red Hat Product Errata RHSA-2026:64790 - Security Advisory Issued: 2026-09-08 Updated: 2026-09-08 RHSA-2026:64790 - Security Advisory Overview Updated Packages Synopsis Critical: 389-ds:1.4 security, bug fix, and enhancement update Type/Severity Security Advisory: Critical Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for the 389-ds:1.4 module is now available for Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support and Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description 389 Directory Server is an LDAP version 3 (LDAPv3) compliant server. The base packages include the Lightweight Directory Access Protocol (LDAP) server and command-line utilities for server administration. Security Fix(es): 389-ds-base: 389-ds-base: heap buffer overflow via SASL wrapped-record length lower-bound underflow in sasl_io_start_packet() (CVE-2026-18355) 389-ds-base: 389-ds-base: pre-authentication NULL pointer dereference via paged results and USE_ONE_BACKEND control in op_shared_search (CVE-2026-18453) 389-ds-base: 389-ds-base: SASL PLAIN authentication allows privilege escalation to Directory Manager via stale identity in Cyrus SASL auxiliary property (CVE-2026-18922) 389-ds-base: 389-ds: anonymous LDAP client can defeat SELFDN ACI bind-rule checks via empty bind DN (CVE-2026-76560) Bug Fix(es) and Enhancement(s): lib389: set nsDS5ReplicaBindDNGroup before ensure_agreement() (JIRA:RHEL-244461) fix breaks replication total init when nsDS5ReplicaBindDNGroup is set after agreement creation (JIRA:RHEL-248760) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life 8.6 x86_64 Red Hat Enterprise Linux Server - AUS 8.6 x86_64 Fixes BZ - 2509186 - CVE-2026-18355 389-ds-base: 389-ds-base: heap buffer overflow via SASL wrapped-record length lower-bound underflow in sasl_io_start_packet() BZ - 2509696 - CVE-2026-18453 389-ds-base: 389-ds-base: pre-authentication NULL pointer dereference via paged results and USE_ONE_BACKEND control in op_shared_search BZ - 2511388 - CVE-2026-18922 389-ds-base: 389-ds-base: SASL PLAIN authentication allows privilege escalation to Directory Manager via stale identity in Cyrus SASL auxiliary property BZ - 2519521 - CVE-2026-76560 389-ds-base: 389-ds: anonymous LDAP client can defeat SELFDN ACI bind-rule checks via empty bind DN CVEs CVE-2026-18355 CVE-2026-18453 CVE-2026-18922 CVE-2026-76560 References https://access.redhat.com/security/updates/classification/#critical Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life 8.6 SRPM 389-ds-base-1.4.3.34-12.module+el8.6.0+24796+4783e9a9.src.rpm SHA-256: 055b4a7a4751a1f1b517f7cf06127eb7a43e32a3d5135d4578f9bd37d5115c11 x86_64 389-ds-base-1.4.3.34-12.module+el8.6.0+24796+4783e9a9.x86_64.rpm SHA-256: f0fa50eb75126ea8b7756d5a2e495015623f393ec98e98b02f2a40d67181f95e 389-ds-base-debuginfo-1.4.3.34-12.module+el8.6.0+24796+4783e9a9.x86_64.rpm SHA-256: 1c575e6a348618dc889f1c9ce5f83d8c9cd5264ed76e48d4e84b723b4de5b76a 389-ds-base-debugsource-1.4.3.34-12.module+el8.6.0+24796+4783e9a9.x86_64.rpm SHA-256: 681c6e2b8fc4544094095f9d72ab0ed294a62abbde04ca9a82654a0540853f7d 389-ds-base-devel-1.4.3.34-12.module+el8.6.0+24796+4783e9a9.x86_64.rpm SHA-256: 4d9408712953b83ea839ff7823b6982bf66060219c41d8676890702a4a85e71e 389-ds-base-legacy-tools-1.4.3.34-12.module+el8.6.0+24796+4783e9a9.x86_64.rpm SHA-256: 33ad239ea3ef765a66e7b6f1e0eeb3dba65cc72bef953d46e16d0b72644f60c1 389-ds-base-legacy-tools-debuginfo-1.4.3.34-12.module+el8.6.0+24796+4783e9a9.x86_64.rpm SHA-256: b332a3953a0818dabb18852f5b2df2b96c646a1d96dc345482ccd5c7e51c1493 389-ds-base-libs-1.4.3.34-12.module+el8.6.0+24796+4783e9a9.x86_64.rpm SHA-256: 1d6aafca8cb3f6fcbec3d5ebd669a86c69d0adcb882b89611292f1053091c8be 389-ds-base-libs-debuginfo-1.4.3.34-12.module+el8.6.0+24796+4783e9a9.x86_64.rpm SHA-256: 134d68e520aee21d10cc4691377b098cb1bcea3ae25021a066cb03c0fa18fb51 389-ds-base-snmp-1.4.3.34-12.module+el8.6.0+24796+4783e9a9.x86_64.rpm SHA-256: 663921a08358630c78f41043f91a0a93a51c77f8666efce057b424b9427a76a5 389-ds-base-snmp-debuginfo-1.4.3.34-12.module+el8.6.0+24796+4783e9a9.x86_64.rpm SHA-256: da848c1867993c9ef119175a821d48345e779174a83e445170e5d0a4bca92368 python3-lib389-1.4.3.34-12.module+el8.6.0+24796+4783e9a9.noarch.rpm SHA-256: f95d03b3673e29f399a6bb02890387f8abc897eacb1803900ebb9567e7fd2457 Red Hat Enterprise Linux Server - AUS 8.6 SRPM 389-ds-base-1.4.3.34-12.module+el8.6.0+24796+4783e9a9.src.rpm SHA-256: 055b4a7a4751a1f1b517f7cf06127eb7a43e32a3d5135d4578f9bd37d5115c11 x86_64 389-ds-base-1.4.3.34-12.module+el8.6.0+24796+4783e9a9.x86_64.rpm SHA-256: f0fa50eb75126ea8b7756d5a2e495015623f393ec98e98b02f2a40d67181f95e 389-ds-base-debuginfo-1.4.3.34-12.module+el8.6.0+24796+4783e9a9.x86_64.rpm SHA-256: 1c575e6a348618dc889f1c9ce5f83d8c9cd5264ed76e48d4e84b723b4de5b76a 389-ds-base-debugsource-1.4.3.34-12.module+el8.6.0+24796+4783e9a9.x86_64.rpm SHA-256: 681c6e2b8fc4544094095f9d72ab0ed294a62abbde04ca9a82654a0540853f7d 389-ds-base-devel-1.4.3.34-12.module+el8.6.0+24796+4783e9a9.x86_64.rpm SHA-256: 4d9408712953b83ea839ff7823b6982bf66060219c41d8676890702a4a85e71e 389-ds-base-legacy-tools-1.4.3.34-12.module+el8.6.0+24796+4783e9a9.x86_64.rpm SHA-256: 33ad239ea3ef765a66e7b6f1e0eeb3dba65cc72bef953d46e16d0b72644f60c1 389-ds-base-legacy-tools-debuginfo-1.4.3.34-12.module+el8.6.0+24796+4783e9a9.x86_64.rpm SHA-256: b332a3953a0818dabb18852f5b2df2b96c646a1d96dc345482ccd5c7e51c1493 389-ds-base-libs-1.4.3.34-12.module+el8.6.0+24796+4783e9a9.x86_64.rpm SHA-256: 1d6aafca8cb3f6fcbec3d5ebd669a86c69d0adcb882b89611292f1053091c8be 389-ds-base-libs-debuginfo-1.4.3.34-12.module+el8.6.0+24796+4783e9a9.x86_64.rpm SHA-256: 134d68e520aee21d10cc4691377b098cb1bcea3ae25021a066cb03c0fa18fb51 389-ds-base-snmp-1.4.3.34-12.module+el8.6.0+24796+4783e9a9.x86_64.rpm SHA-256: 663921a08358630c78f41043f91a0a93a51c77f8666efce057b424b9427a76a5 389-ds-base-snmp-debuginfo-1.4.3.34-12.module+el8.6.0+24796+4783e9a9.x86_64.rpm SHA-256: da848c1867993c9ef119175a821d48345e779174a83e445170e5d0a4bca92368 python3-lib389-1.4.3.34-12.module+el8.6.0+24796+4783e9a9.noarch.rpm SHA-256: f95d03b3673e29f399a6bb02890387f8abc897eacb1803900ebb9567e7fd2457 The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .
A critical update for the 389 Directory Server (389-ds) addresses multiple vulnerabilities, including a heap buffer overflow via SASL wrapped-record length underflow (CVE-2026-18355, CVSS 7.5), a pre-authentication NULL pointer dereference (CVE-2026-18453, CVSS 7.5), and a SASL PLAIN authentication flaw allowing privilege escalation to Directory Manager (CVE-2026-18922, CVSS 9.8). This update applies to the 389-ds:1.4 module on Red Hat Enterprise Linux 8.6 Advanced Mission Critical and Extended Update Support Long-Life Add-On. Administrators should apply the referenced Red Hat errata immediately.