RHSA-2026:64793CriticalCVSS 9.8

Red Hat Security Advisory: redhat-ds:11 security, bug fix, and enhancement update

Published
September 8, 2026
Last Modified
September 25, 2026

🔗 CVE IDs covered (5)

📋 Description

CVE-2026-18355 — 389-ds-base: 389-ds-base: heap buffer overflow via SASL wrapped-record length lower-bound underflow in sasl_io_start_packet() CVE-2026-18453 — 389-ds-base: 389-ds-base: pre-authentication NULL pointer dereference via paged results and USE_ONE_BACKEND control in op_shared_search CVE-2026-18922 — 389-ds-base: 389-ds-base: SASL PLAIN authentication allows privilege escalation to Directory Manager via stale identity in Cyrus SASL auxiliary property CVE-2026-19843 — 389-ds-base: 389-ds-base: Command injection via unescaped LDAP DN in Cockpit 389 Console LDAP editor CVE-2026-76560 — 389-ds-base: 389-ds: anonymous LDAP client can defeat SELFDN ACI bind-rule checks via empty bind DN

🎯 Affected products14

  • Red Hat Directory Server 11.9 for RHEL 8
  • 389-ds-base-0:1.4.3.39-28.module+el8dsrv+24826+9ffa737d.src (redhat-ds:11) as a component of Red Hat Directory Server 11.9 for RHEL 8
  • 389-ds-base-0:1.4.3.39-28.module+el8dsrv+24826+9ffa737d.x86_64 (redhat-ds:11) as a component of Red Hat Directory Server 11.9 for RHEL 8
  • 389-ds-base-debuginfo-0:1.4.3.39-28.module+el8dsrv+24826+9ffa737d.x86_64 (redhat-ds:11) as a component of Red Hat Directory Server 11.9 for RHEL 8
  • 389-ds-base-debugsource-0:1.4.3.39-28.module+el8dsrv+24826+9ffa737d.x86_64 (redhat-ds:11) as a component of Red Hat Directory Server 11.9 for RHEL 8
  • 389-ds-base-devel-0:1.4.3.39-28.module+el8dsrv+24826+9ffa737d.x86_64 (redhat-ds:11) as a component of Red Hat Directory Server 11.9 for RHEL 8
  • 389-ds-base-legacy-tools-0:1.4.3.39-28.module+el8dsrv+24826+9ffa737d.x86_64 (redhat-ds:11) as a component of Red Hat Directory Server 11.9 for RHEL 8
  • 389-ds-base-legacy-tools-debuginfo-0:1.4.3.39-28.module+el8dsrv+24826+9ffa737d.x86_64 (redhat-ds:11) as a component of Red Hat Directory Server 11.9 for RHEL 8
  • 389-ds-base-libs-0:1.4.3.39-28.module+el8dsrv+24826+9ffa737d.x86_64 (redhat-ds:11) as a component of Red Hat Directory Server 11.9 for RHEL 8
  • 389-ds-base-libs-debuginfo-0:1.4.3.39-28.module+el8dsrv+24826+9ffa737d.x86_64 (redhat-ds:11) as a component of Red Hat Directory Server 11.9 for RHEL 8
  • 389-ds-base-snmp-0:1.4.3.39-28.module+el8dsrv+24826+9ffa737d.x86_64 (redhat-ds:11) as a component of Red Hat Directory Server 11.9 for RHEL 8
  • 389-ds-base-snmp-debuginfo-0:1.4.3.39-28.module+el8dsrv+24826+9ffa737d.x86_64 (redhat-ds:11) as a component of Red Hat Directory Server 11.9 for RHEL 8
  • cockpit-389-ds-0:1.4.3.39-28.module+el8dsrv+24826+9ffa737d.noarch (redhat-ds:11) as a component of Red Hat Directory Server 11.9 for RHEL 8
  • python3-lib389-0:1.4.3.39-28.module+el8dsrv+24826+9ffa737d.noarch (redhat-ds:11) as a component of Red Hat Directory Server 11.9 for RHEL 8

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible. Workaround: Administrators can restrict nsslapd-allowed-sasl-mechanisms to only the mechanisms actually required (e.g. GSSAPI, EXTERNAL, GSS-SPNEGO), excluding PLAIN. Since the exploit chain requires the first bind attempt to be a failed SASL PLAIN bind as cn=Directory Manager, removing PLAIN from the allowed mechanism list prevents that step entirely — this blocks both the originally reported variant (valid low-privileged account) and the zero-credential SASL ANONYMOUS variant, since both depend on the same initial PLAIN bind to plant the stale identity. Workaround: Restrict Cockpit 389 Console access to trusted administrators, and restrict delegated LDAP add/rename privileges to trusted accounts, until a fix is available. This issue only affects Red Hat Directory Server deployments that include the Cockpit console; plain RHEL 389-ds-base is not affected. Workaround: Until a fix is available, review all ACIs using userattr="...#SELFDN" bind rules and confirm the target attribute cannot be set to an empty value, or add an explicit authmethod restriction to the ACI to prevent anonymous binds from satisfying the check. Where anonymous binds are not required, disabling anonymous access to the directory removes the attack surface entirely.

🔗 References (9)