elsa-2026-26456

oracle_linux
Description

[3.2.0-8] - Bump version to 3.2.0-8 - Resolves: RHEL-182152 - CVE-2026-11610 389-ds-base: 389-ds-base: Heap buffer overflow in sasl_io_recv() via padded SASL UNBIND [rhel-10.2.z] - Resolves: RHEL-183105 - CVE-2026-11774 389-ds-base: 389-ds-base: integer overflow in SASL packet length bypasses size limit leading to heap buffer overflow [rhel-10.2.z] [3.2.0-7] - Bump version to 3.2.0-7 - Resolves: RHEL-170271 - DS 12 does not handle escape char in bind user [rhel-10.2.z] - Resolves: RHEL-170276 - dnaSharedConfig: 'dnaPortNum: 0' [rhel-10.2.z] - Resolves: RHEL-170281 - Memory leaks in syncrepl plugin during persistent search operations [rhel-10.2.z] - Resolves: RHEL-170363 - access log - suspicious wtime optime negative and large values in internal op [rhel-10.2.z] - Resolves: RHEL-170478 - An online reinitialization with LMDB is terminating the receiving server [rhel-10.2.z] - Resolves: RHEL-170481 - dsctl healthcheck DSMOLE0001 inaccurate recommendations when there is more than 1 LDAP backend [rhel-10.2.z] - Resolves: RHEL-170515 - Possible memory leak when using the Retro Changelog plugin. [rhel-10.2.z] - Resolves: RHEL-174526 - [RFE] Add OS-level thread names to all server threads [rhel-10.2.z] - Resolves: RHEL-178074 - CVE-2026-9064 389-ds-base: 389-ds-base: unbounded LDAP controls count in get_ldapmessage_controls_ext() causes CPU and heap amplification (remote DoS) [rhel-10.2] - Resolves: RHEL-180718 - Online export is failing when using the option '-s' [rhel-10.2.z] - Resolves: RHEL-183897 - Server shutdown during online reindex may lead to data loss [rhel-10.2.z] - Resolves: RHEL-183898 - Error: NssSsl.add_cert() got an unexpected keyword argument 'input_file' [rhel-10.2.z] - Resolves: RHEL-183899 - Replication errors in logs [rhel-10.2.z] - Resolves: RHEL-183900 - Substring index produces empty results and can crash when non-default nsSubStrBegin/nsSubStrEnd lengths are configured [rhel-10.2.z]

Timeline
Published
unknown
Last Modified
unknown
CVSS Details

CVSS details not available.

Affected Products

No product information available.

References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "cves": [
    "CVE-2026-9064"
  ],
  "cvss": 0.0,
  "database_specific": {
    "severity": "IMPORTANT"
  },
  "description": "[3.2.0-8]\n- Bump version to 3.2.0-8\n- Resolves: RHEL-182152 - CVE-2026-11610 389-ds-base: 389-ds-base: Heap\n  buffer overflow in sasl_io_recv() via padded SASL UNBIND [rhel-10.2.z]\n- Resolves: RHEL-183105 - CVE-2026-11774 389-ds-base: 389-ds-base: integer\n  overflow in SASL packet length bypasses size limit leading to heap buffer\n  overflow [rhel-10.2.z]\n\n[3.2.0-7]\n- Bump version to 3.2.0-7\n- Resolves: RHEL-170271 - DS 12 does not handle escape char in bind user\n  [rhel-10.2.z]\n- Resolves: RHEL-170276 - dnaSharedConfig: 'dnaPortNum: 0' [rhel-10.2.z]\n- Resolves: RHEL-170281 - Memory leaks in syncrepl plugin during persistent\n  search operations [rhel-10.2.z]\n- Resolves: RHEL-170363 - access log - suspicious wtime  optime negative\n  and large values in internal op [rhel-10.2.z]\n- Resolves: RHEL-170478 - An online reinitialization with LMDB is\n  terminating the receiving server [rhel-10.2.z]\n- Resolves: RHEL-170481 - dsctl healthcheck DSMOLE0001 inaccurate\n  recommendations when there is more than 1 LDAP backend [rhel-10.2.z]\n- Resolves: RHEL-170515 - Possible memory leak when using the Retro\n  Changelog plugin. [rhel-10.2.z]\n- Resolves: RHEL-174526 - [RFE] Add OS-level thread names to all server\n  threads [rhel-10.2.z]\n- Resolves: RHEL-178074 - CVE-2026-9064 389-ds-base: 389-ds-base: unbounded\n  LDAP controls count in get_ldapmessage_controls_ext() causes CPU and heap\n  amplification (remote DoS) [rhel-10.2]\n- Resolves: RHEL-180718 - Online export is failing when using the option\n  '-s' [rhel-10.2.z]\n- Resolves: RHEL-183897 - Server shutdown during online reindex may lead to\n  data loss [rhel-10.2.z]\n- Resolves: RHEL-183898 - Error: NssSsl.add_cert() got an unexpected\n  keyword argument 'input_file' [rhel-10.2.z]\n- Resolves: RHEL-183899 - Replication errors in logs [rhel-10.2.z]\n- Resolves: RHEL-183900 - Substring index produces empty results and can\n  crash when non-default nsSubStrBegin/nsSubStrEnd lengths are configured\n  [rhel-10.2.z]",
  "id": "ELSA-2026-26456",
  "ovalId": "oval:com.oracle.elsa:def:202626456",
  "source": "oracle_linux",
  "title": "ELSA-2026-26456:  389-ds-base security, bug fix, and enhancement update (IMPORTANT)",
  "url": "https://linux.oracle.com/errata/ELSA-2026-26456.html"
}
View JSON API Download JSON