Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:26452 - Security Advisory
Issued:
2026-06-17
Updated:
2026-06-17

RHSA-2026:26452 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: 389-ds-base security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for 389-ds-base is now available for Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

389 Directory Server is an LDAP version 3 (LDAPv3) compliant server. The base packages include the Lightweight Directory Access Protocol (LDAP) server and command-line utilities for server administration.

Security Fix(es):

  • 389-ds-base: 389-ds-base: unbounded LDAP controls count in get_ldapmessage_controls_ext() causes CPU and heap amplification (remote DoS) (CVE-2026-9064)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server - AUS 9.2 x86_64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2 x86_64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.2 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.2 s390x
  • Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.2 x86_64
  • Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.2 aarch64
  • Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.2 ppc64le
  • Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.2 s390x

Fixes

  • BZ - 2480093 - CVE-2026-9064 389-ds-base: 389-ds-base: unbounded LDAP controls count in get_ldapmessage_controls_ext() causes CPU and heap amplification (remote DoS)

CVEs

  • CVE-2026-9064

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server - AUS 9.2

SRPM
389-ds-base-2.2.4-18.el9_2.src.rpm SHA-256: b4552f8f136ed89ccf8b05344bc282e751d697c6c790b8a01e4308c53491336a
x86_64
389-ds-base-2.2.4-18.el9_2.x86_64.rpm SHA-256: 65b377ead54d29b8b898b2abc1ca3fa018a43aa5c6cea1e48bcb77512f88af1f
389-ds-base-debuginfo-2.2.4-18.el9_2.x86_64.rpm SHA-256: 15413326740b0f5b8002cb113b5d662b15ccd3cd3015fb078b2e701692dd25d7
389-ds-base-debugsource-2.2.4-18.el9_2.x86_64.rpm SHA-256: ed902c236c6a9328e9a2ec2922ad4f16eab955159ff525347692284913469bc0
389-ds-base-libs-2.2.4-18.el9_2.x86_64.rpm SHA-256: bb554f874d854bf79c790d5cc88a3a175ac9ef20aa78f348b6aca2be7b4a4909
389-ds-base-libs-debuginfo-2.2.4-18.el9_2.x86_64.rpm SHA-256: fb2e1fb8cb6828bdcb3982a537833b3387cb2418fbbeed727b9864c20ed1581c
389-ds-base-snmp-debuginfo-2.2.4-18.el9_2.x86_64.rpm SHA-256: c117f031551d89df0166af80c73aff3fc31234bad991442c4d3a5e05f4789d52
python3-lib389-2.2.4-18.el9_2.noarch.rpm SHA-256: f8b45603f111131a80abaa07fd52a8bd92e8c9865a0867cbcc4fdac56d25b3ca

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2

SRPM
389-ds-base-2.2.4-18.el9_2.src.rpm SHA-256: b4552f8f136ed89ccf8b05344bc282e751d697c6c790b8a01e4308c53491336a
ppc64le
389-ds-base-2.2.4-18.el9_2.ppc64le.rpm SHA-256: e4131d81ffbdc993a3956f3f46760a6846d4c450ceef81bbaf7c0b5cfdcf5341
389-ds-base-debuginfo-2.2.4-18.el9_2.ppc64le.rpm SHA-256: 248eda5ec462ea8eee38f2bd5362494c9e466333c44bb06345d160419536cfea
389-ds-base-debugsource-2.2.4-18.el9_2.ppc64le.rpm SHA-256: 64cdaa3ed0870b5b6675a495dad69dd9612f832d4c70e642d5cfcc96f57a1e71
389-ds-base-libs-2.2.4-18.el9_2.ppc64le.rpm SHA-256: f65fd5819410baaf48b11dc2fd13f82afde2f807370488c6e48b6832dbb8dd75
389-ds-base-libs-debuginfo-2.2.4-18.el9_2.ppc64le.rpm SHA-256: 919dc875eb261ba7fa604f54d97761f0bd27ac7df43de7ade90bd4257060a828
389-ds-base-snmp-debuginfo-2.2.4-18.el9_2.ppc64le.rpm SHA-256: 3515af2b210b8e50d297252d6e2812bd664ede3244a2ff64871ca21b153fd445
python3-lib389-2.2.4-18.el9_2.noarch.rpm SHA-256: f8b45603f111131a80abaa07fd52a8bd92e8c9865a0867cbcc4fdac56d25b3ca

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2

SRPM
389-ds-base-2.2.4-18.el9_2.src.rpm SHA-256: b4552f8f136ed89ccf8b05344bc282e751d697c6c790b8a01e4308c53491336a
x86_64
389-ds-base-2.2.4-18.el9_2.x86_64.rpm SHA-256: 65b377ead54d29b8b898b2abc1ca3fa018a43aa5c6cea1e48bcb77512f88af1f
389-ds-base-debuginfo-2.2.4-18.el9_2.x86_64.rpm SHA-256: 15413326740b0f5b8002cb113b5d662b15ccd3cd3015fb078b2e701692dd25d7
389-ds-base-debugsource-2.2.4-18.el9_2.x86_64.rpm SHA-256: ed902c236c6a9328e9a2ec2922ad4f16eab955159ff525347692284913469bc0
389-ds-base-libs-2.2.4-18.el9_2.x86_64.rpm SHA-256: bb554f874d854bf79c790d5cc88a3a175ac9ef20aa78f348b6aca2be7b4a4909
389-ds-base-libs-debuginfo-2.2.4-18.el9_2.x86_64.rpm SHA-256: fb2e1fb8cb6828bdcb3982a537833b3387cb2418fbbeed727b9864c20ed1581c
389-ds-base-snmp-debuginfo-2.2.4-18.el9_2.x86_64.rpm SHA-256: c117f031551d89df0166af80c73aff3fc31234bad991442c4d3a5e05f4789d52
python3-lib389-2.2.4-18.el9_2.noarch.rpm SHA-256: f8b45603f111131a80abaa07fd52a8bd92e8c9865a0867cbcc4fdac56d25b3ca

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.2

SRPM
389-ds-base-2.2.4-18.el9_2.src.rpm SHA-256: b4552f8f136ed89ccf8b05344bc282e751d697c6c790b8a01e4308c53491336a
aarch64
389-ds-base-2.2.4-18.el9_2.aarch64.rpm SHA-256: f1387520a0f358265414a937516e63bfbfaea073f6c32f70ecfad27909579057
389-ds-base-debuginfo-2.2.4-18.el9_2.aarch64.rpm SHA-256: 32cb454342e83deedfd21b36054e8b580aa389d499f0e09ce043169506fce084
389-ds-base-debugsource-2.2.4-18.el9_2.aarch64.rpm SHA-256: f5eb9ccd7d1b9bff636a7c6beb1e04d2401a2c732515a6b7cf98ee32f12ed4d8
389-ds-base-libs-2.2.4-18.el9_2.aarch64.rpm SHA-256: 20b528d86dd038e888a5ab43143bfd54e58d5cc9bac3e3ec8337885dfa6b3176
389-ds-base-libs-debuginfo-2.2.4-18.el9_2.aarch64.rpm SHA-256: c1a7d8f80780c1070db11c61998c3661c36810b62d07cfac1ddcececd04544bb
389-ds-base-snmp-debuginfo-2.2.4-18.el9_2.aarch64.rpm SHA-256: 206ac21a6f9cf068be0c761557d957f58277597b8486c75e5b509a6a27cd29f3
python3-lib389-2.2.4-18.el9_2.noarch.rpm SHA-256: f8b45603f111131a80abaa07fd52a8bd92e8c9865a0867cbcc4fdac56d25b3ca

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.2

SRPM
389-ds-base-2.2.4-18.el9_2.src.rpm SHA-256: b4552f8f136ed89ccf8b05344bc282e751d697c6c790b8a01e4308c53491336a
s390x
389-ds-base-2.2.4-18.el9_2.s390x.rpm SHA-256: 25e3f349fdcc50e2d07629c9b04128ae2da8f43ee4f3c7ce42347e3f3271c2c7
389-ds-base-debuginfo-2.2.4-18.el9_2.s390x.rpm SHA-256: 8a277012182b5c30711a7f1a89068fc7aabf0883cfd352419d1b225a92c32503
389-ds-base-debugsource-2.2.4-18.el9_2.s390x.rpm SHA-256: 87f315e499f1b5af99cf6c8607d0e4825b33e9f946059a80640c9bfe49d1617c
389-ds-base-libs-2.2.4-18.el9_2.s390x.rpm SHA-256: 3ac67b3494da7a3c16934d8d0924e9109d9368609effc7cb9b410165db76d4b4
389-ds-base-libs-debuginfo-2.2.4-18.el9_2.s390x.rpm SHA-256: d1b216942e39eedf187836d4c7a71e6fbeba8fb8033876d9bd12a2609ab5b02e
389-ds-base-snmp-debuginfo-2.2.4-18.el9_2.s390x.rpm SHA-256: aeeb13ac813a3f5b21e59df6a6cf71f3be713acb52a82750e0f120fad38c79e1
python3-lib389-2.2.4-18.el9_2.noarch.rpm SHA-256: f8b45603f111131a80abaa07fd52a8bd92e8c9865a0867cbcc4fdac56d25b3ca

Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.2

SRPM
389-ds-base-2.2.4-18.el9_2.src.rpm SHA-256: b4552f8f136ed89ccf8b05344bc282e751d697c6c790b8a01e4308c53491336a
x86_64
389-ds-base-2.2.4-18.el9_2.x86_64.rpm SHA-256: 65b377ead54d29b8b898b2abc1ca3fa018a43aa5c6cea1e48bcb77512f88af1f
389-ds-base-debuginfo-2.2.4-18.el9_2.x86_64.rpm SHA-256: 15413326740b0f5b8002cb113b5d662b15ccd3cd3015fb078b2e701692dd25d7
389-ds-base-debugsource-2.2.4-18.el9_2.x86_64.rpm SHA-256: ed902c236c6a9328e9a2ec2922ad4f16eab955159ff525347692284913469bc0
389-ds-base-libs-2.2.4-18.el9_2.x86_64.rpm SHA-256: bb554f874d854bf79c790d5cc88a3a175ac9ef20aa78f348b6aca2be7b4a4909
389-ds-base-libs-debuginfo-2.2.4-18.el9_2.x86_64.rpm SHA-256: fb2e1fb8cb6828bdcb3982a537833b3387cb2418fbbeed727b9864c20ed1581c
389-ds-base-snmp-debuginfo-2.2.4-18.el9_2.x86_64.rpm SHA-256: c117f031551d89df0166af80c73aff3fc31234bad991442c4d3a5e05f4789d52
python3-lib389-2.2.4-18.el9_2.noarch.rpm SHA-256: f8b45603f111131a80abaa07fd52a8bd92e8c9865a0867cbcc4fdac56d25b3ca

Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.2

SRPM
389-ds-base-2.2.4-18.el9_2.src.rpm SHA-256: b4552f8f136ed89ccf8b05344bc282e751d697c6c790b8a01e4308c53491336a
aarch64
389-ds-base-2.2.4-18.el9_2.aarch64.rpm SHA-256: f1387520a0f358265414a937516e63bfbfaea073f6c32f70ecfad27909579057
389-ds-base-debuginfo-2.2.4-18.el9_2.aarch64.rpm SHA-256: 32cb454342e83deedfd21b36054e8b580aa389d499f0e09ce043169506fce084
389-ds-base-debugsource-2.2.4-18.el9_2.aarch64.rpm SHA-256: f5eb9ccd7d1b9bff636a7c6beb1e04d2401a2c732515a6b7cf98ee32f12ed4d8
389-ds-base-libs-2.2.4-18.el9_2.aarch64.rpm SHA-256: 20b528d86dd038e888a5ab43143bfd54e58d5cc9bac3e3ec8337885dfa6b3176
389-ds-base-libs-debuginfo-2.2.4-18.el9_2.aarch64.rpm SHA-256: c1a7d8f80780c1070db11c61998c3661c36810b62d07cfac1ddcececd04544bb
389-ds-base-snmp-debuginfo-2.2.4-18.el9_2.aarch64.rpm SHA-256: 206ac21a6f9cf068be0c761557d957f58277597b8486c75e5b509a6a27cd29f3
python3-lib389-2.2.4-18.el9_2.noarch.rpm SHA-256: f8b45603f111131a80abaa07fd52a8bd92e8c9865a0867cbcc4fdac56d25b3ca

Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.2

SRPM
389-ds-base-2.2.4-18.el9_2.src.rpm SHA-256: b4552f8f136ed89ccf8b05344bc282e751d697c6c790b8a01e4308c53491336a
ppc64le
389-ds-base-2.2.4-18.el9_2.ppc64le.rpm SHA-256: e4131d81ffbdc993a3956f3f46760a6846d4c450ceef81bbaf7c0b5cfdcf5341
389-ds-base-debuginfo-2.2.4-18.el9_2.ppc64le.rpm SHA-256: 248eda5ec462ea8eee38f2bd5362494c9e466333c44bb06345d160419536cfea
389-ds-base-debugsource-2.2.4-18.el9_2.ppc64le.rpm SHA-256: 64cdaa3ed0870b5b6675a495dad69dd9612f832d4c70e642d5cfcc96f57a1e71
389-ds-base-libs-2.2.4-18.el9_2.ppc64le.rpm SHA-256: f65fd5819410baaf48b11dc2fd13f82afde2f807370488c6e48b6832dbb8dd75
389-ds-base-libs-debuginfo-2.2.4-18.el9_2.ppc64le.rpm SHA-256: 919dc875eb261ba7fa604f54d97761f0bd27ac7df43de7ade90bd4257060a828
389-ds-base-snmp-debuginfo-2.2.4-18.el9_2.ppc64le.rpm SHA-256: 3515af2b210b8e50d297252d6e2812bd664ede3244a2ff64871ca21b153fd445
python3-lib389-2.2.4-18.el9_2.noarch.rpm SHA-256: f8b45603f111131a80abaa07fd52a8bd92e8c9865a0867cbcc4fdac56d25b3ca

Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.2

SRPM
389-ds-base-2.2.4-18.el9_2.src.rpm SHA-256: b4552f8f136ed89ccf8b05344bc282e751d697c6c790b8a01e4308c53491336a
s390x
389-ds-base-2.2.4-18.el9_2.s390x.rpm SHA-256: 25e3f349fdcc50e2d07629c9b04128ae2da8f43ee4f3c7ce42347e3f3271c2c7
389-ds-base-debuginfo-2.2.4-18.el9_2.s390x.rpm SHA-256: 8a277012182b5c30711a7f1a89068fc7aabf0883cfd352419d1b225a92c32503
389-ds-base-debugsource-2.2.4-18.el9_2.s390x.rpm SHA-256: 87f315e499f1b5af99cf6c8607d0e4825b33e9f946059a80640c9bfe49d1617c
389-ds-base-libs-2.2.4-18.el9_2.s390x.rpm SHA-256: 3ac67b3494da7a3c16934d8d0924e9109d9368609effc7cb9b410165db76d4b4
389-ds-base-libs-debuginfo-2.2.4-18.el9_2.s390x.rpm SHA-256: d1b216942e39eedf187836d4c7a71e6fbeba8fb8033876d9bd12a2609ab5b02e
389-ds-base-snmp-debuginfo-2.2.4-18.el9_2.s390x.rpm SHA-256: aeeb13ac813a3f5b21e59df6a6cf71f3be713acb52a82750e0f120fad38c79e1
python3-lib389-2.2.4-18.el9_2.noarch.rpm SHA-256: f8b45603f111131a80abaa07fd52a8bd92e8c9865a0867cbcc4fdac56d25b3ca

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility