Red Hat Product Errata RHSA-2026:26460 - Security Advisory Issued: 2026-06-17 Updated: 2026-06-17 RHSA-2026:26460 - Security Advisory Overview Updated Packages Synopsis Important: 389-ds:1.4 security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for the 389-ds:1.4 module is now available for Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support and Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description 389 Directory Server is an LDAP version 3 (LDAPv3) compliant server. The base packages include the Lightweight Directory Access Protocol (LDAP) server and command-line utilities for server administration. Security Fix(es): 389-ds-base: 389-ds-base: unbounded LDAP controls count in get_ldapmessage_controls_ext() causes CPU and heap amplification (remote DoS) (CVE-2026-9064) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.6 x86_64 Red Hat Enterprise Linux Server - AUS 8.6 x86_64 Fixes BZ - 2480093 - CVE-2026-9064 389-ds-base: 389-ds-base: unbounded LDAP controls count in get_ldapmessage_controls_ext() causes CPU and heap amplification (remote DoS) CVEs CVE-2026-9064 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.6 SRPM 389-ds-base-1.4.3.34-9.module+el8.6.0+24371+47116d61.src.rpm SHA-256: ee15b265c1cb8265436e87fa969494e252d132141710d22de36e33c84d7fb357 x86_64 389-ds-base-1.4.3.34-9.module+el8.6.0+24371+47116d61.x86_64.rpm SHA-256: 74febc09f4d5e5a98b333713ddc0e2911953c8ea9a95955f35b9c75992864414 389-ds-base-debuginfo-1.4.3.34-9.module+el8.6.0+24371+47116d61.x86_64.rpm SHA-256: b3f833e3ba7a90117f5e2e14207a5d1d9a9d02f390f59555a8f131b11ca88032 389-ds-base-debugsource-1.4.3.34-9.module+el8.6.0+24371+47116d61.x86_64.rpm SHA-256: e7ce630a7fc02dd8696ec374583220b15c82601b208ba613b3cd4617cdc54616 389-ds-base-devel-1.4.3.34-9.module+el8.6.0+24371+47116d61.x86_64.rpm SHA-256: eec59f3854629b85e644846ac9ce822d034a998a3dafde6b7ace0fdf03b37fff 389-ds-base-legacy-tools-1.4.3.34-9.module+el8.6.0+24371+47116d61.x86_64.rpm SHA-256: 7695666a46f6b0bd6de476fba1b5a68ca3812b2e100b9694afdb7f0b087415a2 389-ds-base-legacy-tools-debuginfo-1.4.3.34-9.module+el8.6.0+24371+47116d61.x86_64.rpm SHA-256: 9ae54acd684eec3c49b1eb1079a78502ba39b5b98fc41eedd21413bb82087913 389-ds-base-libs-1.4.3.34-9.module+el8.6.0+24371+47116d61.x86_64.rpm SHA-256: 0f684515f050aceb51c9df3b452b03f9ea0e419d66025ca10d9415dadfffc349 389-ds-base-libs-debuginfo-1.4.3.34-9.module+el8.6.0+24371+47116d61.x86_64.rpm SHA-256: 438282dcde8941ce6a33f4030cfc157b143ed62cea2809a9146ef1c4b3703d78 389-ds-base-snmp-1.4.3.34-9.module+el8.6.0+24371+47116d61.x86_64.rpm SHA-256: c24b1cc5ce86747867039bdc094aaebe49921ffa65eeda381ef6124b793011bc 389-ds-base-snmp-debuginfo-1.4.3.34-9.module+el8.6.0+24371+47116d61.x86_64.rpm SHA-256: bc05a7ab5a028ed05354eceb2d3139e1b608d44fdfe412db1953c5500989e290 python3-lib389-1.4.3.34-9.module+el8.6.0+24371+47116d61.noarch.rpm SHA-256: c423136582114ec77156f1fca6c6bcd55b6d89ea15f6d7af9e03604d1b60226d Red Hat Enterprise Linux Server - AUS 8.6 SRPM 389-ds-base-1.4.3.34-9.module+el8.6.0+24371+47116d61.src.rpm SHA-256: ee15b265c1cb8265436e87fa969494e252d132141710d22de36e33c84d7fb357 x86_64 389-ds-base-1.4.3.34-9.module+el8.6.0+24371+47116d61.x86_64.rpm SHA-256: 74febc09f4d5e5a98b333713ddc0e2911953c8ea9a95955f35b9c75992864414 389-ds-base-debuginfo-1.4.3.34-9.module+el8.6.0+24371+47116d61.x86_64.rpm SHA-256: b3f833e3ba7a90117f5e2e14207a5d1d9a9d02f390f59555a8f131b11ca88032 389-ds-base-debugsource-1.4.3.34-9.module+el8.6.0+24371+47116d61.x86_64.rpm SHA-256: e7ce630a7fc02dd8696ec374583220b15c82601b208ba613b3cd4617cdc54616 389-ds-base-devel-1.4.3.34-9.module+el8.6.0+24371+47116d61.x86_64.rpm SHA-256: eec59f3854629b85e644846ac9ce822d034a998a3dafde6b7ace0fdf03b37fff 389-ds-base-legacy-tools-1.4.3.34-9.module+el8.6.0+24371+47116d61.x86_64.rpm SHA-256: 7695666a46f6b0bd6de476fba1b5a68ca3812b2e100b9694afdb7f0b087415a2 389-ds-base-legacy-tools-debuginfo-1.4.3.34-9.module+el8.6.0+24371+47116d61.x86_64.rpm SHA-256: 9ae54acd684eec3c49b1eb1079a78502ba39b5b98fc41eedd21413bb82087913 389-ds-base-libs-1.4.3.34-9.module+el8.6.0+24371+47116d61.x86_64.rpm SHA-256: 0f684515f050aceb51c9df3b452b03f9ea0e419d66025ca10d9415dadfffc349 389-ds-base-libs-debuginfo-1.4.3.34-9.module+el8.6.0+24371+47116d61.x86_64.rpm SHA-256: 438282dcde8941ce6a33f4030cfc157b143ed62cea2809a9146ef1c4b3703d78 389-ds-base-snmp-1.4.3.34-9.module+el8.6.0+24371+47116d61.x86_64.rpm SHA-256: c24b1cc5ce86747867039bdc094aaebe49921ffa65eeda381ef6124b793011bc 389-ds-base-snmp-debuginfo-1.4.3.34-9.module+el8.6.0+24371+47116d61.x86_64.rpm SHA-256: bc05a7ab5a028ed05354eceb2d3139e1b608d44fdfe412db1953c5500989e290 python3-lib389-1.4.3.34-9.module+el8.6.0+24371+47116d61.noarch.rpm SHA-256: c423136582114ec77156f1fca6c6bcd55b6d89ea15f6d7af9e03604d1b60226d The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .
A critical vulnerability (CVE-2026-9064, CVSS 7.5 HIGH) in 389 Directory Server allows a remote denial-of-service attack by sending an unbounded number of LDAP controls, causing excessive CPU and heap memory consumption. The vulnerability affects Red Hat Directory Server versions 11.0, 12.0, and 13.0, as well as Red Hat Enterprise Linux 6.0. A security update is available for the 389-ds:1.4 module on RHEL 8.6 EUS and AMCUS, with the fixed package version being 389-ds-base-1.4.3.34-9.module+el8.6.0+24371+47116d61.