Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:64778 - Security Advisory
Issued:
2026-09-08
Updated:
2026-09-08

RHSA-2026:64778 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Critical: 389-ds-base security, bug fix, and enhancement update

Type/Severity

Security Advisory: Critical

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for 389-ds-base is now available for Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions.

Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

389 Directory Server is an LDAP version 3 (LDAPv3) compliant server. The base packages include the Lightweight Directory Access Protocol (LDAP) server and command-line utilities for server administration.

Security Fix(es):

  • 389-ds-base: 389-ds-base: heap buffer overflow via SASL wrapped-record length lower-bound underflow in sasl_io_start_packet() (CVE-2026-18355)
  • 389-ds-base: 389-ds-base: pre-authentication NULL pointer dereference via paged results and USE_ONE_BACKEND control in op_shared_search (CVE-2026-18453)
  • 389-ds-base: 389-ds-base: SASL PLAIN authentication allows privilege escalation to Directory Manager via stale identity in Cyrus SASL auxiliary property (CVE-2026-18922)
  • 389-ds-base: 389-ds: anonymous LDAP client can defeat SELFDN ACI bind-rule checks via empty bind DN (CVE-2026-76560)

Bug Fix(es) and Enhancement(s):

  • lib389: set nsDS5ReplicaBindDNGroup before ensure_agreement() (JIRA:RHEL-244464)
  • fix breaks replication total init when nsDS5ReplicaBindDNGroup is set after agreement creation (JIRA:RHEL-248763)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server - AUS 9.2 x86_64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2 x86_64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.2 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.2 s390x
  • Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.2 x86_64
  • Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.2 aarch64
  • Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.2 ppc64le
  • Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.2 s390x

Fixes

  • BZ - 2509186 - CVE-2026-18355 389-ds-base: 389-ds-base: heap buffer overflow via SASL wrapped-record length lower-bound underflow in sasl_io_start_packet()
  • BZ - 2509696 - CVE-2026-18453 389-ds-base: 389-ds-base: pre-authentication NULL pointer dereference via paged results and USE_ONE_BACKEND control in op_shared_search
  • BZ - 2511388 - CVE-2026-18922 389-ds-base: 389-ds-base: SASL PLAIN authentication allows privilege escalation to Directory Manager via stale identity in Cyrus SASL auxiliary property
  • BZ - 2519521 - CVE-2026-76560 389-ds-base: 389-ds: anonymous LDAP client can defeat SELFDN ACI bind-rule checks via empty bind DN

CVEs

  • CVE-2026-18355
  • CVE-2026-18453
  • CVE-2026-18922
  • CVE-2026-76560

References

  • https://access.redhat.com/security/updates/classification/#critical
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server - AUS 9.2

SRPM
389-ds-base-2.2.4-22.el9_2.src.rpm SHA-256: 129944f090619d5e52fa93d0336095f6137dd5133a21f3028aaf83f8e3705667
x86_64
389-ds-base-2.2.4-22.el9_2.x86_64.rpm SHA-256: e940ac57899a5196c5e8bbea27d52729cfd97ff960796376f6bcb66e2eef67bb
389-ds-base-debuginfo-2.2.4-22.el9_2.x86_64.rpm SHA-256: a5ce93d1956bb24195ecefee6a44d4dceec07d3d3dcf46879ccec0ddf5ca05e1
389-ds-base-debugsource-2.2.4-22.el9_2.x86_64.rpm SHA-256: 06b203e77e7f582b5cf8a20355d5d0ae344c4013f8af920bbf41e760c479ea8e
389-ds-base-libs-2.2.4-22.el9_2.x86_64.rpm SHA-256: fa73c137e96837b6198410ae1e7866592fcf20f759aa8868d088d76cbd4c161f
389-ds-base-libs-debuginfo-2.2.4-22.el9_2.x86_64.rpm SHA-256: 1874f727aad4bea60d383dc708cd3cc5c535b87a0428deb3be666fbe815ccded
389-ds-base-snmp-debuginfo-2.2.4-22.el9_2.x86_64.rpm SHA-256: 377df18354427d0bfa504853e24ed2f479021172056c4bf9df5a7ac9fdb208a5
python3-lib389-2.2.4-22.el9_2.noarch.rpm SHA-256: 159749ab3dad8d0cdd733265544ff244458c7e3a808eb7590b0ad15fe63cca34

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2

SRPM
389-ds-base-2.2.4-22.el9_2.src.rpm SHA-256: 129944f090619d5e52fa93d0336095f6137dd5133a21f3028aaf83f8e3705667
ppc64le
389-ds-base-2.2.4-22.el9_2.ppc64le.rpm SHA-256: bec0b853e0fa68de232c14abb71aeb3393382243502ce96deba9a8f2a5e0a3b1
389-ds-base-debuginfo-2.2.4-22.el9_2.ppc64le.rpm SHA-256: a71228a369952a46ba3c39c34ec62f4a6210900dd920f6874ed3acf354a3b848
389-ds-base-debugsource-2.2.4-22.el9_2.ppc64le.rpm SHA-256: 6749c8992de244801a2ea9db0b13b3f373e6691dc79a34ca2aeea75e2b826bfd
389-ds-base-libs-2.2.4-22.el9_2.ppc64le.rpm SHA-256: ec67a3d8ffa640274f307a4746bd2533a67ca6d66e3907381913c07b4d3e4532
389-ds-base-libs-debuginfo-2.2.4-22.el9_2.ppc64le.rpm SHA-256: 4206d01dda741081aaa838596dcfc548de1dd1b5cd8f5041ffb6aa62814feb78
389-ds-base-snmp-debuginfo-2.2.4-22.el9_2.ppc64le.rpm SHA-256: 78f470cc73fa2d57c915e169269aaa938fcc2ffa5fd159ef8bc656d6740cb355
python3-lib389-2.2.4-22.el9_2.noarch.rpm SHA-256: 159749ab3dad8d0cdd733265544ff244458c7e3a808eb7590b0ad15fe63cca34

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2

SRPM
389-ds-base-2.2.4-22.el9_2.src.rpm SHA-256: 129944f090619d5e52fa93d0336095f6137dd5133a21f3028aaf83f8e3705667
x86_64
389-ds-base-2.2.4-22.el9_2.x86_64.rpm SHA-256: e940ac57899a5196c5e8bbea27d52729cfd97ff960796376f6bcb66e2eef67bb
389-ds-base-debuginfo-2.2.4-22.el9_2.x86_64.rpm SHA-256: a5ce93d1956bb24195ecefee6a44d4dceec07d3d3dcf46879ccec0ddf5ca05e1
389-ds-base-debugsource-2.2.4-22.el9_2.x86_64.rpm SHA-256: 06b203e77e7f582b5cf8a20355d5d0ae344c4013f8af920bbf41e760c479ea8e
389-ds-base-libs-2.2.4-22.el9_2.x86_64.rpm SHA-256: fa73c137e96837b6198410ae1e7866592fcf20f759aa8868d088d76cbd4c161f
389-ds-base-libs-debuginfo-2.2.4-22.el9_2.x86_64.rpm SHA-256: 1874f727aad4bea60d383dc708cd3cc5c535b87a0428deb3be666fbe815ccded
389-ds-base-snmp-debuginfo-2.2.4-22.el9_2.x86_64.rpm SHA-256: 377df18354427d0bfa504853e24ed2f479021172056c4bf9df5a7ac9fdb208a5
python3-lib389-2.2.4-22.el9_2.noarch.rpm SHA-256: 159749ab3dad8d0cdd733265544ff244458c7e3a808eb7590b0ad15fe63cca34

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.2

SRPM
389-ds-base-2.2.4-22.el9_2.src.rpm SHA-256: 129944f090619d5e52fa93d0336095f6137dd5133a21f3028aaf83f8e3705667
aarch64
389-ds-base-2.2.4-22.el9_2.aarch64.rpm SHA-256: d852c55fc5a348958f1f2aa191dcb5d5bbad77937002ef5475b3c2b6c1724a2e
389-ds-base-debuginfo-2.2.4-22.el9_2.aarch64.rpm SHA-256: 13c84d70230300f8fedcdde79cb52b6cf3630055a1c9d9a8b36cc57576e220dc
389-ds-base-debugsource-2.2.4-22.el9_2.aarch64.rpm SHA-256: 3a044fb0ee93d0e7bd0660104fed24cd2877ec0a8b433deeb4ad917488dc2b42
389-ds-base-libs-2.2.4-22.el9_2.aarch64.rpm SHA-256: b9626e41e28b1c73b963b598587300be03ae3ad26cd86ccb51c88621699c9b84
389-ds-base-libs-debuginfo-2.2.4-22.el9_2.aarch64.rpm SHA-256: 41e9c0c3ee8ced868e3b9dae74f51a21bd4140c549c602f70522df18c7a815ff
389-ds-base-snmp-debuginfo-2.2.4-22.el9_2.aarch64.rpm SHA-256: 2f84ba53758a4ce0d100a452521d7a721fa4a06ea68d36708ff49bb660cf07cb
python3-lib389-2.2.4-22.el9_2.noarch.rpm SHA-256: 159749ab3dad8d0cdd733265544ff244458c7e3a808eb7590b0ad15fe63cca34

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.2

SRPM
389-ds-base-2.2.4-22.el9_2.src.rpm SHA-256: 129944f090619d5e52fa93d0336095f6137dd5133a21f3028aaf83f8e3705667
s390x
389-ds-base-2.2.4-22.el9_2.s390x.rpm SHA-256: 7fb07970c29e5f85ee8104be78146b2723e16b0dc03dc345323a1406c02583c5
389-ds-base-debuginfo-2.2.4-22.el9_2.s390x.rpm SHA-256: 0383a8e9802d8966f522154b77c1f6768158ba9ed3e5b87f80c34d57e872cf1a
389-ds-base-debugsource-2.2.4-22.el9_2.s390x.rpm SHA-256: dbf28b6738a4eda72d7fa2c78a822c50c49aac03d70a534320e28f7252ad6974
389-ds-base-libs-2.2.4-22.el9_2.s390x.rpm SHA-256: 14a2c1d659f000efa24a38a0b1c25975f0bc4bc7fd67bca597450a9907d5c763
389-ds-base-libs-debuginfo-2.2.4-22.el9_2.s390x.rpm SHA-256: 1031e0f82e48a33fceab7d1bdf7953dde0d404ccf3440bf3986488b93b68642a
389-ds-base-snmp-debuginfo-2.2.4-22.el9_2.s390x.rpm SHA-256: 96163b42ad4a462da5a723e0ab7c28604c6146b62b0efb0b3cb647820f6ee8d6
python3-lib389-2.2.4-22.el9_2.noarch.rpm SHA-256: 159749ab3dad8d0cdd733265544ff244458c7e3a808eb7590b0ad15fe63cca34

Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.2

SRPM
389-ds-base-2.2.4-22.el9_2.src.rpm SHA-256: 129944f090619d5e52fa93d0336095f6137dd5133a21f3028aaf83f8e3705667
x86_64
389-ds-base-2.2.4-22.el9_2.x86_64.rpm SHA-256: e940ac57899a5196c5e8bbea27d52729cfd97ff960796376f6bcb66e2eef67bb
389-ds-base-debuginfo-2.2.4-22.el9_2.x86_64.rpm SHA-256: a5ce93d1956bb24195ecefee6a44d4dceec07d3d3dcf46879ccec0ddf5ca05e1
389-ds-base-debugsource-2.2.4-22.el9_2.x86_64.rpm SHA-256: 06b203e77e7f582b5cf8a20355d5d0ae344c4013f8af920bbf41e760c479ea8e
389-ds-base-libs-2.2.4-22.el9_2.x86_64.rpm SHA-256: fa73c137e96837b6198410ae1e7866592fcf20f759aa8868d088d76cbd4c161f
389-ds-base-libs-debuginfo-2.2.4-22.el9_2.x86_64.rpm SHA-256: 1874f727aad4bea60d383dc708cd3cc5c535b87a0428deb3be666fbe815ccded
389-ds-base-snmp-debuginfo-2.2.4-22.el9_2.x86_64.rpm SHA-256: 377df18354427d0bfa504853e24ed2f479021172056c4bf9df5a7ac9fdb208a5
python3-lib389-2.2.4-22.el9_2.noarch.rpm SHA-256: 159749ab3dad8d0cdd733265544ff244458c7e3a808eb7590b0ad15fe63cca34

Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.2

SRPM
389-ds-base-2.2.4-22.el9_2.src.rpm SHA-256: 129944f090619d5e52fa93d0336095f6137dd5133a21f3028aaf83f8e3705667
aarch64
389-ds-base-2.2.4-22.el9_2.aarch64.rpm SHA-256: d852c55fc5a348958f1f2aa191dcb5d5bbad77937002ef5475b3c2b6c1724a2e
389-ds-base-debuginfo-2.2.4-22.el9_2.aarch64.rpm SHA-256: 13c84d70230300f8fedcdde79cb52b6cf3630055a1c9d9a8b36cc57576e220dc
389-ds-base-debugsource-2.2.4-22.el9_2.aarch64.rpm SHA-256: 3a044fb0ee93d0e7bd0660104fed24cd2877ec0a8b433deeb4ad917488dc2b42
389-ds-base-libs-2.2.4-22.el9_2.aarch64.rpm SHA-256: b9626e41e28b1c73b963b598587300be03ae3ad26cd86ccb51c88621699c9b84
389-ds-base-libs-debuginfo-2.2.4-22.el9_2.aarch64.rpm SHA-256: 41e9c0c3ee8ced868e3b9dae74f51a21bd4140c549c602f70522df18c7a815ff
389-ds-base-snmp-debuginfo-2.2.4-22.el9_2.aarch64.rpm SHA-256: 2f84ba53758a4ce0d100a452521d7a721fa4a06ea68d36708ff49bb660cf07cb
python3-lib389-2.2.4-22.el9_2.noarch.rpm SHA-256: 159749ab3dad8d0cdd733265544ff244458c7e3a808eb7590b0ad15fe63cca34

Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.2

SRPM
389-ds-base-2.2.4-22.el9_2.src.rpm SHA-256: 129944f090619d5e52fa93d0336095f6137dd5133a21f3028aaf83f8e3705667
ppc64le
389-ds-base-2.2.4-22.el9_2.ppc64le.rpm SHA-256: bec0b853e0fa68de232c14abb71aeb3393382243502ce96deba9a8f2a5e0a3b1
389-ds-base-debuginfo-2.2.4-22.el9_2.ppc64le.rpm SHA-256: a71228a369952a46ba3c39c34ec62f4a6210900dd920f6874ed3acf354a3b848
389-ds-base-debugsource-2.2.4-22.el9_2.ppc64le.rpm SHA-256: 6749c8992de244801a2ea9db0b13b3f373e6691dc79a34ca2aeea75e2b826bfd
389-ds-base-libs-2.2.4-22.el9_2.ppc64le.rpm SHA-256: ec67a3d8ffa640274f307a4746bd2533a67ca6d66e3907381913c07b4d3e4532
389-ds-base-libs-debuginfo-2.2.4-22.el9_2.ppc64le.rpm SHA-256: 4206d01dda741081aaa838596dcfc548de1dd1b5cd8f5041ffb6aa62814feb78
389-ds-base-snmp-debuginfo-2.2.4-22.el9_2.ppc64le.rpm SHA-256: 78f470cc73fa2d57c915e169269aaa938fcc2ffa5fd159ef8bc656d6740cb355
python3-lib389-2.2.4-22.el9_2.noarch.rpm SHA-256: 159749ab3dad8d0cdd733265544ff244458c7e3a808eb7590b0ad15fe63cca34

Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.2

SRPM
389-ds-base-2.2.4-22.el9_2.src.rpm SHA-256: 129944f090619d5e52fa93d0336095f6137dd5133a21f3028aaf83f8e3705667
s390x
389-ds-base-2.2.4-22.el9_2.s390x.rpm SHA-256: 7fb07970c29e5f85ee8104be78146b2723e16b0dc03dc345323a1406c02583c5
389-ds-base-debuginfo-2.2.4-22.el9_2.s390x.rpm SHA-256: 0383a8e9802d8966f522154b77c1f6768158ba9ed3e5b87f80c34d57e872cf1a
389-ds-base-debugsource-2.2.4-22.el9_2.s390x.rpm SHA-256: dbf28b6738a4eda72d7fa2c78a822c50c49aac03d70a534320e28f7252ad6974
389-ds-base-libs-2.2.4-22.el9_2.s390x.rpm SHA-256: 14a2c1d659f000efa24a38a0b1c25975f0bc4bc7fd67bca597450a9907d5c763
389-ds-base-libs-debuginfo-2.2.4-22.el9_2.s390x.rpm SHA-256: 1031e0f82e48a33fceab7d1bdf7953dde0d404ccf3440bf3986488b93b68642a
389-ds-base-snmp-debuginfo-2.2.4-22.el9_2.s390x.rpm SHA-256: 96163b42ad4a462da5a723e0ab7c28604c6146b62b0efb0b3cb647820f6ee8d6
python3-lib389-2.2.4-22.el9_2.noarch.rpm SHA-256: 159749ab3dad8d0cdd733265544ff244458c7e3a808eb7590b0ad15fe63cca34

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility