Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:26456: Important: 389-ds-base security, bug fix, and enhancement update

A remote denial-of-service vulnerability (CVE-2026-9064, CVSS 7.5 HIGH) exists in 389-ds-base where an unbounded LDAP controls count in the `get_ldapmessage_controls_ext()` function leads to CPU and heap amplification. The vulnerability affects Red Hat Directory Server versions 11.0, 12.0, and 13.0, as well as Red Hat Enterprise Linux 6.0. Red Hat has released an update to address this issue; administrators should apply the patch for their specific RHEL 10.x version as referenced in advisory RHSA-2026:26456.
Read Full Article →

Red Hat Product Errata RHSA-2026:26456 - Security Advisory Issued: 2026-06-17 Updated: 2026-06-17 RHSA-2026:26456 - Security Advisory Overview Updated Packages Synopsis Important: 389-ds-base security, bug fix, and enhancement update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for 389-ds-base is now available for Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description 389 Directory Server is an LDAP version 3 (LDAPv3) compliant server. The base packages include the Lightweight Directory Access Protocol (LDAP) server and command-line utilities for server administration. Security Fix(es): 389-ds-base: 389-ds-base: unbounded LDAP controls count in get_ldapmessage_controls_ext() causes CPU and heap amplification (remote DoS) (CVE-2026-9064) Bug Fix(es) and Enhancement(s): DS 12 does not handle escape char in bind user [rhel-10.2.z] (JIRA:RHEL-170271) dnaSharedConfig: "dnaPortNum: 0" [rhel-10.2.z] (JIRA:RHEL-170276) Memory leaks in syncrepl plugin during persistent search operations [rhel-10.2.z] (JIRA:RHEL-170281) access log - suspicious wtime optime negative and large values in internal op [rhel-10.2.z] (JIRA:RHEL-170363) An online reinitialization with LMDB is terminating the receiving server [rhel-10.2.z] (JIRA:RHEL-170478) dsctl healthcheck DSMOLE0001 inaccurate recommendations when there is more than 1 LDAP backend [rhel-10.2.z] (JIRA:RHEL-170481) Possible memory leak when using the Retro Changelog plugin. [rhel-10.2.z] (JIRA:RHEL-170515) [RFE] Add OS-level thread names to all server threads [rhel-10.2.z] (JIRA:RHEL-174526) Online export is failing when using the option "-s" [rhel-10.2.z] (JIRA:RHEL-180718) Server shutdown during online reindex may lead to data loss [rhel-10.2.z] (JIRA:RHEL-183897) Error: NssSsl.add_cert() got an unexpected keyword argument 'input_file' [rhel-10.2.z] (JIRA:RHEL-183898) Replication errors in logs [rhel-10.2.z] (JIRA:RHEL-183899) Substring index produces empty results and can crash when non-default nsSubStrBegin/nsSubStrEnd lengths are configured [rhel-10.2.z] (JIRA:RHEL-183900) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 10 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 x86_64 Red Hat Enterprise Linux for IBM z Systems 10 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 s390x Red Hat Enterprise Linux for Power, little endian 10 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat Enterprise Linux for ARM 64 10 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat CodeReady Linux Builder for x86_64 10 x86_64 Red Hat CodeReady Linux Builder for Power, little endian 10 ppc64le Red Hat CodeReady Linux Builder for ARM 64 10 aarch64 Red Hat CodeReady Linux Builder for IBM z Systems 10 s390x Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 10.2 x86_64 Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 10.2 s390x Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.2 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.2 s390x Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.2 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.2 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 10.2 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 10.2 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 10.2 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 10.2 s390x Fixes BZ - 2480093 - CVE-2026-9064 389-ds-base: 389-ds-base: unbounded LDAP controls count in get_ldapmessage_controls_ext() causes CPU and heap amplification (remote DoS) CVEs CVE-2026-9064 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 10 SRPM 389-ds-base-3.2.0-7.el10_2.src.rpm SHA-256: 09ebef52fecd044d056d382f9381f9e3a214cd957a00a1e49a90f4d591418d66 x86_64 389-ds-base-3.2.0-7.el10_2.x86_64.rpm SHA-256: 8d41df3d11ade952358d45ccb36c3415caaeda51dbfec0846c6fa658415a1a8f 389-ds-base-bdb-debuginfo-3.2.0-7.el10_2.x86_64.rpm SHA-256: 0d6918e5e1b4cf9e865a09c6482820a63518017e68719f4300f75cc3338ff717 389-ds-base-debuginfo-3.2.0-7.el10_2.x86_64.rpm SHA-256: 02fe30fdfbd5262233b6678595697c283a7150f26120449786d6cde7df6a387c 389-ds-base-debugsource-3.2.0-7.el10_2.x86_64.rpm SHA-256: 19c3d883bcf206e455d97765ee694e0c807484b92ae36de4c4e16f24254444e5 389-ds-base-libs-3.2.0-7.el10_2.x86_64.rpm SHA-256: 8c941a08bbd151561aa41e2c9de6a28445b9b690a7d141e29314fae0319a928c 389-ds-base-libs-debuginfo-3.2.0-7.el10_2.x86_64.rpm SHA-256: 5ef7258fdd7bee7be6d4a31a7af61d330a8904a77db559c75fe62703f01a3436 389-ds-base-snmp-3.2.0-7.el10_2.x86_64.rpm SHA-256: 3d5746fd023b7e819d0f2312f6c942b8bbd1adaf4e613301814aad874335310a 389-ds-base-snmp-debuginfo-3.2.0-7.el10_2.x86_64.rpm SHA-256: d3cdbe149ca71b2d22b2948dba2bd7948671d418480f5c27e1822852c460fd0c python3-lib389-3.2.0-7.el10_2.noarch.rpm SHA-256: e4f17c5fd802022624ae68be5b226b354e97f0a01f44537530328682f419bdfe Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 SRPM 389-ds-base-3.2.0-7.el10_2.src.rpm SHA-256: 09ebef52fecd044d056d382f9381f9e3a214cd957a00a1e49a90f4d591418d66 x86_64 389-ds-base-3.2.0-7.el10_2.x86_64.rpm SHA-256: 8d41df3d11ade952358d45ccb36c3415caaeda51dbfec0846c6fa658415a1a8f 389-ds-base-bdb-debuginfo-3.2.0-7.el10_2.x86_64.rpm SHA-256: 0d6918e5e1b4cf9e865a09c6482820a63518017e68719f4300f75cc3338ff717 389-ds-base-debuginfo-3.2.0-7.el10_2.x86_64.rpm SHA-256: 02fe30fdfbd5262233b6678595697c283a7150f26120449786d6cde7df6a387c 389-ds-base-debugsource-3.2.0-7.el10_2.x86_64.rpm SHA-256: 19c3d883bcf206e455d97765ee694e0c807484b92ae36de4c4e16f24254444e5 389-ds-base-libs-3.2.0-7.el10_2.x86_64.rpm SHA-256: 8c941a08bbd151561aa41e2c9de6a28445b9b690a7d141e29314fae0319a928c 389-ds-base-libs-debuginfo-3.2.0-7.el10_2.x86_64.rpm SHA-256: 5ef7258fdd7bee7be6d4a31a7af61d330a8904a77db559c75fe62703f01a3436 389-ds-base-snmp-3.2.0-7.el10_2.x86_64.rpm SHA-256: 3d5746fd023b7e819d0f2312f6c942b8bbd1adaf4e613301814aad874335310a 389-ds-base-snmp-debuginfo-3.2.0-7.el10_2.x86_64.rpm SHA-256: d3cdbe149ca71b2d22b2948dba2bd7948671d418480f5c27e1822852c460fd0c python3-lib389-3.2.0-7.el10_2.noarch.rpm SHA-256: e4f17c5fd802022624ae68be5b226b354e97f0a01f44537530328682f419bdfe Red Hat Enterprise Linux for IBM z Systems 10 SRPM 389-ds-base-3.2.0-7.el10_2.src.rpm SHA-256: 09ebef52fecd044d056d382f9381f9e3a214cd957a00a1e49a90f4d591418d66 s390x 389-ds-base-3.2.0-7.el10_2.s390x.rpm SHA-256: 926206d8d2be8b5342607eb6929938fc21d7b80e3221bc30092d7dcabea36823 389-ds-base-bdb-debuginfo-3.2.0-7.el10_2.s390x.rpm SHA-256: 39cf3f252b0a4fb591283b6a719e63aac7fbfecc3b58170ff279d41d1d518a08 389-ds-base-debuginfo-3.2.0-7.el10_2.s390x.rpm SHA-256: 54ea0d38208d8c3b96f64e54a6799f819b0817da9fea2f13b3c2160aab20eaff 389-ds-base-debugsource-3.2.0-7.el10_2.s390x.rpm SHA-256: 13e601d2dbe92ff9483b8a0b3cf78d1d828c7a498728a839472e231b356212d5 389-ds-base-libs-3.2.0-7.el10_2.s390x.rpm SHA-256: 961bba0635bb1c3ba0764aeb0d67d28c3f6a1b37dcc08e8cfee9e818fa7d4f98 389-ds-base-libs-debuginfo-3.2.0-7.el10_2.s390x.rpm SHA-256: b9937072a87260b57775139d7f3e9abeb1c0f24f0fdab30ca48b6286bcbb23c3 389-ds-base-snmp-3.2.0-7.el10_2.s390x.rpm SHA-256: 87eaf6eccdcb5875b3cf3ed90ad1bbfced4fe769e82162dcc18896683d8b8a73 389-ds-base-snmp-debuginfo-3.2.0-7.el10_2.s390x.rpm SHA-256: 94f3324be98e1545532a06a0a68d991e1a5108db49b10a3316caa3d7bd46093f python3-lib389-3.2.0-7.el10_2.noarch.rpm SHA-256: e4f17c5fd802022624ae68be5b226b354e97f0a01f44537530328682f419bdfe Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 SRPM 389-ds-base-3.2.0-7.el10_2.src.rpm SHA-256: 09ebef52fecd044d056d382f9381f9e3a214cd957a00a1e49a90f4d591418d66 s390x 389-ds-base-3.2.0-7.el10_2.s390x.rpm SHA-256: 926206d8d2be8b5342607eb6929938fc21d7b80e3221bc30092d7dcabea36823 389-ds-base-bdb-debuginfo-3.2.0-7.el10_2.s390x.rpm SHA-256: 39cf3f252b0a4fb591283b6a719e63aac7fbfecc3b58170ff279d41d1d518a08 389-ds-base-debuginfo-3.2.0-7.el10_2.s390x.rpm SHA-256: 54ea0d38208d8c3b96f64e54a6799f819b0817da9fea2f13b3c2160aab20eaff 389-ds-base-debugsource-3.2.0-7.el10_2.s390x.rpm SHA-256: 13e601d2dbe92ff9483b8a0b3cf78d1d828c7a498728a839472e231b356212d5 389-ds-base-libs-3.2.0-7.el10_2.s390x.rpm SHA-256: 961bba0635bb1c3ba0764aeb0d67d28c3f6a1b37dcc08e8cfee9e818fa7d4f98 389-ds-base-libs-debuginfo-3.2.0-7.el10_2.s390x.rpm SHA-256: b9937072a87260b57775139d7f3e9abeb1c0f24f0fdab30ca48b6286bcbb23c3 389-ds-base-snmp-3.2.0-7.el10_2.s390x.rpm SHA-256: 87eaf6eccdcb5875b3cf3ed90ad1bbfced4fe769e82162dcc18896683d8b8a73 389-ds-base-snmp-debuginfo-3.2.0-7.el10_2.s390x.rpm SHA-256: 94f3324be98e1545532a06a0a68d991e1a5108db49b10a3316caa3d7bd46093f python3-lib389-3.2.0-7.el10_2.noarch.rpm SHA-256: e4f17c5fd802022624ae68be5b226b354e97f0a01f44537530328682f419bdfe Red Hat Enterprise Linux for Power, little endian 10 SRPM 389-ds-base-3.2.0-7.el10_2.src.

Share this article