VYPR

rpm package

almalinux/389-ds-base-bdb

pkg:rpm/almalinux/389-ds-base-bdb

Vulnerabilities (11)

  • CVE-2026-18922CriSep 7, 2026
    affected < 3.2.0-10.el10_2fixed 3.2.0-10.el10_2

    A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent, unrelated successful bind, regardless of which SASL me

  • CVE-2026-18453HigSep 7, 2026
    affected < 3.2.0-10.el10_2fixed 3.2.0-10.el10_2

    A flaw was found in 389 Directory Server. A missing NULL pointer check in the paged results handling of op_shared_search allows an unauthenticated remote attacker to crash the LDAP server by sending a crafted sequence of search requests using the USE_ONE_BACKEND control, resultin

  • CVE-2026-18355HigSep 7, 2026
    affected < 3.2.0-10.el10_2fixed 3.2.0-10.el10_2

    A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), the wrapped-record length read from the wire is validated only against an upper bound. A small wire length (0, 1, or 2) produces an encrypted_buffer_count

  • CVE-2026-76560HigSep 7, 2026
    affected < 3.2.0-10.el10_2fixed 3.2.0-10.el10_2

    A flaw was found in 389 Directory Server. The SELFDN ACI bind-rule evaluator incorrectly matches an anonymous LDAP client's empty bind DN against an empty stored attribute value, allowing an unauthenticated client to satisfy access control checks intended to require a matching au

  • CVE-2026-78701MedAug 25, 2026
    affected < 3.2.0-10.el10_2fixed 3.2.0-10.el10_2

    A flaw was found in 389-ds-base. A remote, authenticated attacker could exploit a vulnerability in the Simple Authentication and Security Layer (SASL) UNBIND process. By sending a specially crafted request, the attacker can cause a connection to stall, leading to resource exhaust

  • CVE-2026-15722HigJul 31, 2026
    affected < 3.2.0-9.el10_2fixed 3.2.0-9.el10_2

    A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without bounds checking. A remote unauthenticated at

  • CVE-2026-11770HigJul 31, 2026
    affected < 3.2.0-9.el10_2fixed 3.2.0-9.el10_2

    A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated replication plugin privileges and

  • CVE-2026-11610HigJul 7, 2026
    affected < 3.2.0-8.el10_2fixed 3.2.0-8.el10_2

    A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). After a successful SASL bind with integrity protection (SSF > 0), an authenticated attacker can send a specially crafted oversized LDAP UNBIND packet that is copied into a 512-byte

  • CVE-2026-11774HigJun 11, 2026
    affected < 3.2.0-8.el10_2fixed 3.2.0-8.el10_2

    An integer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), adding sizeof(uint32_t) to a crafted SASL packet length prefix of 0xFFFFFFFC causes unsigned wraparound to zero, bypassing the nsslapd-maxsasliosize limit an

  • CVE-2026-11788MedJun 9, 2026
    affected < 3.2.0-9.el10_2fixed 3.2.0-9.el10_2

    A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing an unauthenticated remote attacker to crash the LDAP server when the system is under memory pressure.

  • CVE-2025-14905HigFeb 23, 2026
    affected < 3.1.3-7.el10_1fixed 3.1.3-7.el10_1

    A flaw was found in the 389-ds-base server. A heap buffer overflow vulnerability exists in the `schema_attr_enum_callback` function within the `schema.c` file. This occurs because the code incorrectly calculates the buffer size by summing alias string lengths without accounting f