{
  "cves": [
    "CVE-2026-9064"
  ],
  "cvss": 0.0,
  "database_specific": {
    "severity": "IMPORTANT"
  },
  "description": "[2.8.0-7]\n- Resolves: RHEL-152356 - Getting 'build_candidate_list - Database error 11' messages after migrating to LMDB. [rhel-9.8.z]\n- Resolves: RHEL-168967 - Web console doesn't show the sub suffix of ou=foo,ou=people,dc=example,dc=com. [rhel-9.8.z]\n- Resolves: RHEL-170269 - DS 12 does not handle escape char in bind user [rhel-9.8.z]\n- Resolves: RHEL-174524 - [RFE] Add OS-level thread names to all server threads [rhel-9.8.z]\n- Resolves: RHEL-178086 - CVE-2026-9064 389-ds-base: 389-ds-base: unbounded LDAP controls count in get_ldapmessage_controls_ext() causes CPU and heap amplification (remote DoS) [rhel-9.8]\n- Resolves: RHEL-180716 - Online export is failing when using the option '-s' [rhel-9.8.z]\n- Resolves: RHEL-183895 - Server shutdown during online reindex may lead to data loss [rhel-9.8.z]",
  "id": "ELSA-2026-26455",
  "ovalId": "oval:com.oracle.elsa:def:202626455",
  "source": "oracle_linux",
  "title": "ELSA-2026-26455:  389-ds-base security, bug fix, and enhancement update (IMPORTANT)",
  "url": "https://linux.oracle.com/errata/ELSA-2026-26455.html"
}