Red Hat Security Advisory: 389-ds:1.4 security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2026-11770 — 389-ds-base: 389-ds-base: pre-auth LDAP filter injection in CleanAllRUV status check CVE-2026-11788 — 389-ds-base: 389-ds-base: NULL pointer dereference in deref control plugin BER parser CVE-2026-15722 — 389-ds-base: 389-ds-base: pre-authentication stack buffer overflow in get_ruvelement_from_berval() via unbounded replica ID parsing
🎯 Affected products43
- Red Hat Enterprise Linux AppStream (v. 8)
- 389-ds-base-0:1.4.3.39-26.module+el8.10.0+24634+ded7774b.aarch64 (389-ds:1.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- 389-ds-base-0:1.4.3.39-26.module+el8.10.0+24634+ded7774b.ppc64le (389-ds:1.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- 389-ds-base-0:1.4.3.39-26.module+el8.10.0+24634+ded7774b.s390x (389-ds:1.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- 389-ds-base-0:1.4.3.39-26.module+el8.10.0+24634+ded7774b.src (389-ds:1.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- 389-ds-base-0:1.4.3.39-26.module+el8.10.0+24634+ded7774b.x86_64 (389-ds:1.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- 389-ds-base-debuginfo-0:1.4.3.39-26.module+el8.10.0+24634+ded7774b.aarch64 (389-ds:1.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- 389-ds-base-debuginfo-0:1.4.3.39-26.module+el8.10.0+24634+ded7774b.ppc64le (389-ds:1.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- 389-ds-base-debuginfo-0:1.4.3.39-26.module+el8.10.0+24634+ded7774b.s390x (389-ds:1.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- 389-ds-base-debuginfo-0:1.4.3.39-26.module+el8.10.0+24634+ded7774b.x86_64 (389-ds:1.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- 389-ds-base-debugsource-0:1.4.3.39-26.module+el8.10.0+24634+ded7774b.aarch64 (389-ds:1.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- 389-ds-base-debugsource-0:1.4.3.39-26.module+el8.10.0+24634+ded7774b.ppc64le (389-ds:1.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- 389-ds-base-debugsource-0:1.4.3.39-26.module+el8.10.0+24634+ded7774b.s390x (389-ds:1.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- 389-ds-base-debugsource-0:1.4.3.39-26.module+el8.10.0+24634+ded7774b.x86_64 (389-ds:1.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- 389-ds-base-devel-0:1.4.3.39-26.module+el8.10.0+24634+ded7774b.aarch64 (389-ds:1.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- 389-ds-base-devel-0:1.4.3.39-26.module+el8.10.0+24634+ded7774b.ppc64le (389-ds:1.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- 389-ds-base-devel-0:1.4.3.39-26.module+el8.10.0+24634+ded7774b.s390x (389-ds:1.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- 389-ds-base-devel-0:1.4.3.39-26.module+el8.10.0+24634+ded7774b.x86_64 (389-ds:1.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- 389-ds-base-legacy-tools-0:1.4.3.39-26.module+el8.10.0+24634+ded7774b.aarch64 (389-ds:1.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- 389-ds-base-legacy-tools-0:1.4.3.39-26.module+el8.10.0+24634+ded7774b.ppc64le (389-ds:1.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- 389-ds-base-legacy-tools-0:1.4.3.39-26.module+el8.10.0+24634+ded7774b.s390x (389-ds:1.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- 389-ds-base-legacy-tools-0:1.4.3.39-26.module+el8.10.0+24634+ded7774b.x86_64 (389-ds:1.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- 389-ds-base-legacy-tools-debuginfo-0:1.4.3.39-26.module+el8.10.0+24634+ded7774b.aarch64 (389-ds:1.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- 389-ds-base-legacy-tools-debuginfo-0:1.4.3.39-26.module+el8.10.0+24634+ded7774b.ppc64le (389-ds:1.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- 389-ds-base-legacy-tools-debuginfo-0:1.4.3.39-26.module+el8.10.0+24634+ded7774b.s390x (389-ds:1.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- 389-ds-base-legacy-tools-debuginfo-0:1.4.3.39-26.module+el8.10.0+24634+ded7774b.x86_64 (389-ds:1.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- 389-ds-base-libs-0:1.4.3.39-26.module+el8.10.0+24634+ded7774b.aarch64 (389-ds:1.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- 389-ds-base-libs-0:1.4.3.39-26.module+el8.10.0+24634+ded7774b.ppc64le (389-ds:1.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- 389-ds-base-libs-0:1.4.3.39-26.module+el8.10.0+24634+ded7774b.s390x (389-ds:1.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- 389-ds-base-libs-0:1.4.3.39-26.module+el8.10.0+24634+ded7774b.x86_64 (389-ds:1.4) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- +13 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Set nsslapd-allow-anonymous-access to rootdse or off. Restrict LDAP ports to trusted networks. Monitor for extop OID 2.16.840.1.113730.3.6.8. Use strong replication manager passwords. Workaround: Disable the deref plugin (most effective): dsconf <instance> plugin deref disable; systemctl restart dirsrv@<instance>. Disable anonymous access (nsslapd-allow-anonymous-access=off) to raise the bar from pre-auth to authenticated exploitation. Configure memory limits as defense-in-depth: set nsslapd-maxbersize and nsslapd-conntablesize, and deploy in a cgroup with memory limits. Workaround: Disable anonymous access by setting nsslapd-allow-anonymous-access to 'off' or 'rootdse' in cn=config. Alternatively, restrict network access to the LDAP port to trusted replication partners only using firewall rules.
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2026:55530
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2484802
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2485423
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2499961
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_55530.json