rpm package
almalinux/389-ds-base-bdb
pkg:rpm/almalinux/389-ds-base-bdb
Vulnerabilities (11)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-18922 | Cri | 9.8 | < 3.2.0-10.el10_2 | 3.2.0-10.el10_2 | Sep 7, 2026 | A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent, unrelated successful bind, regardless of which SASL me | |
| CVE-2026-18453 | Hig | 7.5 | < 3.2.0-10.el10_2 | 3.2.0-10.el10_2 | Sep 7, 2026 | A flaw was found in 389 Directory Server. A missing NULL pointer check in the paged results handling of op_shared_search allows an unauthenticated remote attacker to crash the LDAP server by sending a crafted sequence of search requests using the USE_ONE_BACKEND control, resultin | |
| CVE-2026-18355 | Hig | 7.5 | < 3.2.0-10.el10_2 | 3.2.0-10.el10_2 | Sep 7, 2026 | A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), the wrapped-record length read from the wire is validated only against an upper bound. A small wire length (0, 1, or 2) produces an encrypted_buffer_count | |
| CVE-2026-76560 | Hig | 7.5 | < 3.2.0-10.el10_2 | 3.2.0-10.el10_2 | Sep 7, 2026 | A flaw was found in 389 Directory Server. The SELFDN ACI bind-rule evaluator incorrectly matches an anonymous LDAP client's empty bind DN against an empty stored attribute value, allowing an unauthenticated client to satisfy access control checks intended to require a matching au | |
| CVE-2026-78701 | Med | 6.5 | < 3.2.0-10.el10_2 | 3.2.0-10.el10_2 | Aug 25, 2026 | A flaw was found in 389-ds-base. A remote, authenticated attacker could exploit a vulnerability in the Simple Authentication and Security Layer (SASL) UNBIND process. By sending a specially crafted request, the attacker can cause a connection to stall, leading to resource exhaust | |
| CVE-2026-15722 | Hig | 7.5 | < 3.2.0-9.el10_2 | 3.2.0-9.el10_2 | Jul 31, 2026 | A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without bounds checking. A remote unauthenticated at | |
| CVE-2026-11770 | Hig | 7.5 | < 3.2.0-9.el10_2 | 3.2.0-9.el10_2 | Jul 31, 2026 | A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated replication plugin privileges and | |
| CVE-2026-11610 | Hig | 8.8 | < 3.2.0-8.el10_2 | 3.2.0-8.el10_2 | Jul 7, 2026 | A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). After a successful SASL bind with integrity protection (SSF > 0), an authenticated attacker can send a specially crafted oversized LDAP UNBIND packet that is copied into a 512-byte | |
| CVE-2026-11774 | Hig | 7.6 | < 3.2.0-8.el10_2 | 3.2.0-8.el10_2 | Jun 11, 2026 | An integer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), adding sizeof(uint32_t) to a crafted SASL packet length prefix of 0xFFFFFFFC causes unsigned wraparound to zero, bypassing the nsslapd-maxsasliosize limit an | |
| CVE-2026-11788 | Med | 5.9 | < 3.2.0-9.el10_2 | 3.2.0-9.el10_2 | Jun 9, 2026 | A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing an unauthenticated remote attacker to crash the LDAP server when the system is under memory pressure. | |
| CVE-2025-14905 | Hig | 7.2 | < 3.1.3-7.el10_1 | 3.1.3-7.el10_1 | Feb 23, 2026 | A flaw was found in the 389-ds-base server. A heap buffer overflow vulnerability exists in the `schema_attr_enum_callback` function within the `schema.c` file. This occurs because the code incorrectly calculates the buffer size by summing alias string lengths without accounting f |
- affected < 3.2.0-10.el10_2fixed 3.2.0-10.el10_2
A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent, unrelated successful bind, regardless of which SASL me
- affected < 3.2.0-10.el10_2fixed 3.2.0-10.el10_2
A flaw was found in 389 Directory Server. A missing NULL pointer check in the paged results handling of op_shared_search allows an unauthenticated remote attacker to crash the LDAP server by sending a crafted sequence of search requests using the USE_ONE_BACKEND control, resultin
- affected < 3.2.0-10.el10_2fixed 3.2.0-10.el10_2
A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), the wrapped-record length read from the wire is validated only against an upper bound. A small wire length (0, 1, or 2) produces an encrypted_buffer_count
- affected < 3.2.0-10.el10_2fixed 3.2.0-10.el10_2
A flaw was found in 389 Directory Server. The SELFDN ACI bind-rule evaluator incorrectly matches an anonymous LDAP client's empty bind DN against an empty stored attribute value, allowing an unauthenticated client to satisfy access control checks intended to require a matching au
- affected < 3.2.0-10.el10_2fixed 3.2.0-10.el10_2
A flaw was found in 389-ds-base. A remote, authenticated attacker could exploit a vulnerability in the Simple Authentication and Security Layer (SASL) UNBIND process. By sending a specially crafted request, the attacker can cause a connection to stall, leading to resource exhaust
- affected < 3.2.0-9.el10_2fixed 3.2.0-9.el10_2
A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without bounds checking. A remote unauthenticated at
- affected < 3.2.0-9.el10_2fixed 3.2.0-9.el10_2
A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated replication plugin privileges and
- affected < 3.2.0-8.el10_2fixed 3.2.0-8.el10_2
A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). After a successful SASL bind with integrity protection (SSF > 0), an authenticated attacker can send a specially crafted oversized LDAP UNBIND packet that is copied into a 512-byte
- affected < 3.2.0-8.el10_2fixed 3.2.0-8.el10_2
An integer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), adding sizeof(uint32_t) to a crafted SASL packet length prefix of 0xFFFFFFFC causes unsigned wraparound to zero, bypassing the nsslapd-maxsasliosize limit an
- affected < 3.2.0-9.el10_2fixed 3.2.0-9.el10_2
A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing an unauthenticated remote attacker to crash the LDAP server when the system is under memory pressure.
- affected < 3.1.3-7.el10_1fixed 3.1.3-7.el10_1
A flaw was found in the 389-ds-base server. A heap buffer overflow vulnerability exists in the `schema_attr_enum_callback` function within the `schema.c` file. This occurs because the code incorrectly calculates the buffer size by summing alias string lengths without accounting f