Red Hat Product Errata RHSA-2026:26465 - Security Advisory Issued: 2026-06-17 Updated: 2026-06-17 RHSA-2026:26465 - Security Advisory Overview Updated Packages Synopsis Important: 389-ds-base security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for 389-ds-base is now available for Red Hat Enterprise Linux 9.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description 389 Directory Server is an LDAP version 3 (LDAPv3) compliant server. The base packages include the Lightweight Directory Access Protocol (LDAP) server and command-line utilities for server administration. Security Fix(es): 389-ds-base: 389-ds-base: unbounded LDAP controls count in get_ldapmessage_controls_ext() causes CPU and heap amplification (remote DoS) (CVE-2026-9064) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6 x86_64 Red Hat Enterprise Linux Server - AUS 9.6 x86_64 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.6 s390x Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.6 ppc64le Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.6 aarch64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.6 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.6 x86_64 Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 9.6 x86_64 Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 9.6 ppc64le Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 9.6 s390x Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 9.6 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.6 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.6 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.6 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.6 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.6 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.6 s390x Fixes BZ - 2480093 - CVE-2026-9064 389-ds-base: 389-ds-base: unbounded LDAP controls count in get_ldapmessage_controls_ext() causes CPU and heap amplification (remote DoS) CVEs CVE-2026-9064 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6 SRPM 389-ds-base-2.6.1-21.el9_6.src.rpm SHA-256: 8c0e72792b052a8860fb9e28ca473fe30e751d9f288d22dbb2e384dfe2ceb9b0 x86_64 389-ds-base-2.6.1-21.el9_6.x86_64.rpm SHA-256: b38ed93b782062e54b12344c5466f7e66cb85808a497b6e577cefda4c45b2f15 389-ds-base-debuginfo-2.6.1-21.el9_6.x86_64.rpm SHA-256: 9191efef20ea3b6618b494d5257bbb4ba6e4ddf9f9ab1c6ac4fa6e588ec8a719 389-ds-base-debugsource-2.6.1-21.el9_6.x86_64.rpm SHA-256: 23f2c7cd3cde9a0a3a4775e5de1dbac627f71006149fc14b590dd48858b1e9eb 389-ds-base-libs-2.6.1-21.el9_6.x86_64.rpm SHA-256: bcc13f2e4c229e441d133a884923633818d04101e7952ff964a8f4e962e15e8e 389-ds-base-libs-debuginfo-2.6.1-21.el9_6.x86_64.rpm SHA-256: 86cda7b5a3ba1933f02c660ddea85d9d2e83a3f21174c5126f426ebde2fe6b0e 389-ds-base-snmp-2.6.1-21.el9_6.x86_64.rpm SHA-256: 8687c8393edfc4c5d45b7d60e59cae58d6864599988f08596eb2bde9840d0a51 389-ds-base-snmp-debuginfo-2.6.1-21.el9_6.x86_64.rpm SHA-256: f756a206616acfb0a8195314d57438168106aaea601152475ce4b1d951c9bda5 python3-lib389-2.6.1-21.el9_6.noarch.rpm SHA-256: a8a0dee2593a2d00657e5ab894460726ea3da2052109e2217e734e943dc3ce0b Red Hat Enterprise Linux Server - AUS 9.6 SRPM 389-ds-base-2.6.1-21.el9_6.src.rpm SHA-256: 8c0e72792b052a8860fb9e28ca473fe30e751d9f288d22dbb2e384dfe2ceb9b0 x86_64 389-ds-base-2.6.1-21.el9_6.x86_64.rpm SHA-256: b38ed93b782062e54b12344c5466f7e66cb85808a497b6e577cefda4c45b2f15 389-ds-base-debuginfo-2.6.1-21.el9_6.x86_64.rpm SHA-256: 9191efef20ea3b6618b494d5257bbb4ba6e4ddf9f9ab1c6ac4fa6e588ec8a719 389-ds-base-debugsource-2.6.1-21.el9_6.x86_64.rpm SHA-256: 23f2c7cd3cde9a0a3a4775e5de1dbac627f71006149fc14b590dd48858b1e9eb 389-ds-base-libs-2.6.1-21.el9_6.x86_64.rpm SHA-256: bcc13f2e4c229e441d133a884923633818d04101e7952ff964a8f4e962e15e8e 389-ds-base-libs-debuginfo-2.6.1-21.el9_6.x86_64.rpm SHA-256: 86cda7b5a3ba1933f02c660ddea85d9d2e83a3f21174c5126f426ebde2fe6b0e 389-ds-base-snmp-2.6.1-21.el9_6.x86_64.rpm SHA-256: 8687c8393edfc4c5d45b7d60e59cae58d6864599988f08596eb2bde9840d0a51 389-ds-base-snmp-debuginfo-2.6.1-21.el9_6.x86_64.rpm SHA-256: f756a206616acfb0a8195314d57438168106aaea601152475ce4b1d951c9bda5 python3-lib389-2.6.1-21.el9_6.noarch.rpm SHA-256: a8a0dee2593a2d00657e5ab894460726ea3da2052109e2217e734e943dc3ce0b Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.6 SRPM 389-ds-base-2.6.1-21.el9_6.src.rpm SHA-256: 8c0e72792b052a8860fb9e28ca473fe30e751d9f288d22dbb2e384dfe2ceb9b0 s390x 389-ds-base-2.6.1-21.el9_6.s390x.rpm SHA-256: 00caf2faf9a7dd5b51537ce14e328423e0c21260f8a9387233e73fef64ee1eb5 389-ds-base-debuginfo-2.6.1-21.el9_6.s390x.rpm SHA-256: 59010435fb9456e737bcc91585085fc6da8b2f26fa39eb31ed0677b1ea1b72b8 389-ds-base-debugsource-2.6.1-21.el9_6.s390x.rpm SHA-256: aa60e861cf5e2a737478e33d0e037b08ff0afc94798b3074412dc59cf3f5c314 389-ds-base-libs-2.6.1-21.el9_6.s390x.rpm SHA-256: 7b3b7c493546046045557a17fa1cbd71bf5aa624d0bf60bcd80aa51f089b273d 389-ds-base-libs-debuginfo-2.6.1-21.el9_6.s390x.rpm SHA-256: 41934c694b9dffc10e51e8fe232f0e3e210f7c3901b6877565d0e18e2578dd12 389-ds-base-snmp-2.6.1-21.el9_6.s390x.rpm SHA-256: ec36176c55bcde45ad18bc2d3afec2f12fa679bffc44abd429487344f1c23fd7 389-ds-base-snmp-debuginfo-2.6.1-21.el9_6.s390x.rpm SHA-256: 83c39e6795af2fffaa343d142598075314916f8bfc52960baae4ce4c5bed75ea python3-lib389-2.6.1-21.el9_6.noarch.rpm SHA-256: a8a0dee2593a2d00657e5ab894460726ea3da2052109e2217e734e943dc3ce0b Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.6 SRPM 389-ds-base-2.6.1-21.el9_6.src.rpm SHA-256: 8c0e72792b052a8860fb9e28ca473fe30e751d9f288d22dbb2e384dfe2ceb9b0 ppc64le 389-ds-base-2.6.1-21.el9_6.ppc64le.rpm SHA-256: 920753f66120e73b79c6c69e50cb2cd428265c143f21cbf7cb008831696d357c 389-ds-base-debuginfo-2.6.1-21.el9_6.ppc64le.rpm SHA-256: e4eafaa36b5f70958bd24aae2ae64ddc127bf4c042f49293ffa15d969b4eed26 389-ds-base-debugsource-2.6.1-21.el9_6.ppc64le.rpm SHA-256: e99b30060304842b1d48ad44c90c2b6f0467501040a117d0fbf863c8d472c147 389-ds-base-libs-2.6.1-21.el9_6.ppc64le.rpm SHA-256: 42b408f3fe6736514c580543b51554cebc448cdd65bfa00acb6b9834dd1117e2 389-ds-base-libs-debuginfo-2.6.1-21.el9_6.ppc64le.rpm SHA-256: fcc355d9c03281a5c2cee25b2e9db08b4b925fb0eb3cdf21b133c6ae0b84276d 389-ds-base-snmp-2.6.1-21.el9_6.ppc64le.rpm SHA-256: e6ee64005f554b1b90e9686e446602e48fdc31936ab4ffd80a8b6709720dc7e4 389-ds-base-snmp-debuginfo-2.6.1-21.el9_6.ppc64le.rpm SHA-256: 2dc0aa49d78b9e4b500ec371a8bfbf6c71f69a588d8a32e393c5f8375262c996 python3-lib389-2.6.1-21.el9_6.noarch.rpm SHA-256: a8a0dee2593a2d00657e5ab894460726ea3da2052109e2217e734e943dc3ce0b Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.6 SRPM 389-ds-base-2.6.1-21.el9_6.src.rpm SHA-256: 8c0e72792b052a8860fb9e28ca473fe30e751d9f288d22dbb2e384dfe2ceb9b0 aarch64 389-ds-base-2.6.1-21.el9_6.aarch64.rpm SHA-256: 11203a0f66b23dbb5fea87f506e54f82f431aacfb43853c63d40123fc7887b77 389-ds-base-debuginfo-2.6.1-21.el9_6.aarch64.rpm SHA-256: 609d2845117b9959a5c1e8f9b534fd9e03778575e8f845b10143a4045cb06832 389-ds-base-debugsource-2.6.1-21.el9_6.aarch64.rpm SHA-256: 2587417787ee707bc2d45d6edcc37642caa982238ea486e35d8d41b214b981a4 389-ds-base-libs-2.6.1-21.el9_6.aarch64.rpm SHA-256: ad483fc7294d3937435f6c7725ed63daaba77d84025634c4e9e9113df79179fb 389-ds-base-libs-debuginfo-2.6.1-21.el9_6.aarch64.rpm SHA-256: 45a9142d9dea96e058570c795ad7680ef5e04dc97f7be6178243be1b50b765cf 389-ds-base-snmp-2.6.1-21.el9_6.aarch64.rpm SHA-256: c2090112a883a73d90979a87fa2bce0e2d7038ab5d28e2dd540611f118051a8a 389-ds-base-snmp-debuginfo-2.6.1-21.el9_6.aarch64.rpm SHA-256: 1a11cc636f01990705571857a8294a7e2c1d4d1b2ce4d4c2811a82574266520e python3-lib389-2.6.1-21.el9_6.noarch.rpm SHA-256: a8a0dee2593a2d00657e5ab894460726ea3da2052109e2217e734e943dc3ce0b Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.6 SRPM 389-ds-base-2.6.1-21.el9_6.src.rpm SHA-256: 8c0e72792b052a8860fb9e28ca473fe30e751d9f288d22dbb2e384dfe2ceb9b0 ppc64le 389-ds-base-2.6.1-21.el9_6.ppc64le.rpm SHA-256: 920753f66120e73b79c6c69e50cb2cd428265c143f21cbf7cb008831696d357c 389-ds-base-debuginfo-2.6.1-21.el9_6.ppc64le.rpm SHA-256: e4eafaa36b5f70958bd24aae2ae64ddc127bf4c042f49293ffa15d969b4eed26 389-ds-base-debugsource-2.6.1-21.el9_6.ppc64le.rpm SHA-256: e99b30060304842b1d48ad44c90c2b6f0467501040a117d0fbf863c8d472c147 389-ds-base-libs-2.6.1-21.el9_6.ppc64le.rpm SHA-256: 42b408f3fe6736514c580543b51554cebc448cdd65bfa00acb6b9834dd1117e2 389-ds-base-libs-debuginfo-2.6.1-21.el9_6.ppc64le.rpm SHA-256: fcc355d9c03281a5c2cee25b2e9db08b4b925fb0eb3cdf21b133c6ae0b84276d 389-ds-base-snmp-2.6.1-21.el9_6.ppc64le.rpm SHA-256: e6ee64005f554b1b90e9686e446602e48fdc31936ab4ffd80a8b6709720dc7e4 389-ds-base-snmp-debuginfo-2.6.1-21.el9_6.ppc64le.rpm SHA-256: 2dc0aa49d78b9e4b500ec371a8bfbf6c71f69a588d8a32e393c5f8375262c996 python3
A remote denial-of-service vulnerability (CVE-2026-9064, CVSS 7.5 HIGH) exists in 389-ds-base where an unbounded LDAP controls count in the `get_ldapmessage_controls_ext()` function causes CPU and heap amplification. The vulnerability affects Red Hat Directory Server versions 11.0, 12.0, and 13.0, as well as Red Hat Enterprise Linux 6.0. Red Hat has released an important security update for 389-ds-base to address this issue.