- Issued:
- 2026-09-08
- Updated:
- 2026-09-08
RHSA-2026:64792 - Security Advisory
Synopsis
Critical: redhat-ds:11 security, bug fix, and enhancement update
Type/Severity
Security Advisory: Critical
Red Hat Lightspeed patch analysis
Identify and remediate systems affected by this advisory.
Topic
An update for the redhat-ds:11 module is now available for Red Hat Directory Server 11.7 E4S for RHEL 8.
Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
Description
Red Hat Directory Server is an LDAPv3-compliant directory server. The suite of packages includes the Lightweight Directory Access Protocol (LDAP) server, as well as command-line utilities and Web UI packages for server administration.
Security Fix(es):
- 389-ds-base: 389-ds-base: heap buffer overflow via SASL wrapped-record length lower-bound underflow in sasl_io_start_packet() (CVE-2026-18355)
- 389-ds-base: 389-ds-base: pre-authentication NULL pointer dereference via paged results and USE_ONE_BACKEND control in op_shared_search (CVE-2026-18453)
- 389-ds-base: 389-ds-base: SASL PLAIN authentication allows privilege escalation to Directory Manager via stale identity in Cyrus SASL auxiliary property (CVE-2026-18922)
- 389-ds-base: 389-ds-base: Command injection via unescaped LDAP DN in Cockpit 389 Console LDAP editor (CVE-2026-19843)
- 389-ds-base: 389-ds: anonymous LDAP client can defeat SELFDN ACI bind-rule checks via empty bind DN (CVE-2026-76560)
Bug Fix(es) and Enhancement(s):
- lib389: set nsDS5ReplicaBindDNGroup before ensure_agreement() [dirsrv-11.7.z] (JIRA:DIRSRV-866)
- fix breaks replication total init when nsDS5ReplicaBindDNGroup is set after agreement creation [dirsrv-11.7.z] (JIRA:DIRSRV-898)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Solution
For details on how to apply this update, which includes the changes described in this advisory, refer to:
Affected Products
- Red Hat Directory Server - 4 years of updates 11 for RHEL 8.8 x86_64
Fixes
- BZ - 2509186 - CVE-2026-18355 389-ds-base: 389-ds-base: heap buffer overflow via SASL wrapped-record length lower-bound underflow in sasl_io_start_packet()
- BZ - 2509696 - CVE-2026-18453 389-ds-base: 389-ds-base: pre-authentication NULL pointer dereference via paged results and USE_ONE_BACKEND control in op_shared_search
- BZ - 2511388 - CVE-2026-18922 389-ds-base: 389-ds-base: SASL PLAIN authentication allows privilege escalation to Directory Manager via stale identity in Cyrus SASL auxiliary property
- BZ - 2515965 - CVE-2026-19843 389-ds-base: 389-ds-base: Command injection via unescaped LDAP DN in Cockpit 389 Console LDAP editor
- BZ - 2519521 - CVE-2026-76560 389-ds-base: 389-ds: anonymous LDAP client can defeat SELFDN ACI bind-rule checks via empty bind DN
Red Hat Directory Server - 4 years of updates 11 for RHEL 8.8
| SRPM | |
|---|---|
| 389-ds-base-1.4.3.34-18.module+el8dsrv+24812+0acb1821.src.rpm | SHA-256: 73155d0d3b1dccedadfea55df197533df205c8ee0f9a9b840288fe4fe515e820 |
| x86_64 | |
| 389-ds-base-1.4.3.34-18.module+el8dsrv+24812+0acb1821.x86_64.rpm | SHA-256: 81d829a95cb68fbfe589ac74b3f570dec4597e9d2dde366f8610ed15d3eebbbe |
| 389-ds-base-debuginfo-1.4.3.34-18.module+el8dsrv+24812+0acb1821.x86_64.rpm | SHA-256: 08b31367ed01a797cc7b263e279d78810443e250af95eed134bfd45915d7434d |
| 389-ds-base-debugsource-1.4.3.34-18.module+el8dsrv+24812+0acb1821.x86_64.rpm | SHA-256: cb07701ea3845c1e07ece18142f75e8b789af7372a41be79fa939ee798251bbe |
| 389-ds-base-devel-1.4.3.34-18.module+el8dsrv+24812+0acb1821.x86_64.rpm | SHA-256: ba5e892b74c8f5cab400838485b37629c543968f1375d4258b535aefc07f0b7a |
| 389-ds-base-legacy-tools-1.4.3.34-18.module+el8dsrv+24812+0acb1821.x86_64.rpm | SHA-256: 62711506e194dfa8755516e00e760f2dd1702bc5a8f89f67bdd0673d74167958 |
| 389-ds-base-legacy-tools-debuginfo-1.4.3.34-18.module+el8dsrv+24812+0acb1821.x86_64.rpm | SHA-256: f1e79e21a700f971c41ebc935621bc973b8a370b05f04e5baba6c3b1717a80e7 |
| 389-ds-base-libs-1.4.3.34-18.module+el8dsrv+24812+0acb1821.x86_64.rpm | SHA-256: 80c1ee9d5784ff4263925d740a002aba72a24641053090e065acea5984194678 |
| 389-ds-base-libs-debuginfo-1.4.3.34-18.module+el8dsrv+24812+0acb1821.x86_64.rpm | SHA-256: 4fc3a243f5db13b6ba11743bf2750fb3e38f8b304b41a21ef9f4e806e0af3071 |
| 389-ds-base-snmp-1.4.3.34-18.module+el8dsrv+24812+0acb1821.x86_64.rpm | SHA-256: 3191defedb8243c619e22263739c9a4bd2c865afef578950b6aba76a7ca72fa8 |
| 389-ds-base-snmp-debuginfo-1.4.3.34-18.module+el8dsrv+24812+0acb1821.x86_64.rpm | SHA-256: 0413454934e38bfc61080f3336a9baa335c2dce616e89290bd984e290e00753b |
| cockpit-389-ds-1.4.3.34-18.module+el8dsrv+24812+0acb1821.noarch.rpm | SHA-256: 87cafe20d08a8180df3b790c48c61c0b6392e02728c76cbc027146cca16355fe |
| python3-lib389-1.4.3.34-18.module+el8dsrv+24812+0acb1821.noarch.rpm | SHA-256: ca9b1700c2ead0077c9c3319d8f808fbbf090719e84f9f47c338d743bfcd1a20 |
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.