{"cves":["CVE-2026-9064"],"cvss":0.0,"database_specific":{"severity":"IMPORTANT"},"description":"[2.8.0-7]\n- Resolves: RHEL-152356 - Getting 'build_candidate_list - Database error 11' messages after migrating to LMDB. [rhel-9.8.z]\n- Resolves: RHEL-168967 - Web console doesn't show the sub suffix of ou=foo,ou=people,dc=example,dc=com. [rhel-9.8.z]\n- Resolves: RHEL-170269 - DS 12 does not handle escape char in bind user [rhel-9.8.z]\n- Resolves: RHEL-174524 - [RFE] Add OS-level thread names to all server threads [rhel-9.8.z]\n- Resolves: RHEL-178086 - CVE-2026-9064 389-ds-base: 389-ds-base: unbounded LDAP controls count in get_ldapmessage_controls_ext() causes CPU and heap amplification (remote DoS) [rhel-9.8]\n- Resolves: RHEL-180716 - Online export is failing when using the option '-s' [rhel-9.8.z]\n- Resolves: RHEL-183895 - Server shutdown during online reindex may lead to data loss [rhel-9.8.z]","id":"ELSA-2026-26455","ovalId":"oval:com.oracle.elsa:def:202626455","source":"oracle_linux","title":"ELSA-2026-26455:  389-ds-base security, bug fix, and enhancement update (IMPORTANT)","url":"https://linux.oracle.com/errata/ELSA-2026-26455.html"}