Red Hat Product Errata RHSA-2026:26455 - Security Advisory Issued: 2026-06-17 Updated: 2026-06-17 RHSA-2026:26455 - Security Advisory Overview Updated Packages Synopsis Important: 389-ds-base security, bug fix, and enhancement update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for 389-ds-base is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description 389 Directory Server is an LDAP version 3 (LDAPv3) compliant server. The base packages include the Lightweight Directory Access Protocol (LDAP) server and command-line utilities for server administration. Security Fix(es): 389-ds-base: 389-ds-base: unbounded LDAP controls count in get_ldapmessage_controls_ext() causes CPU and heap amplification (remote DoS) (CVE-2026-9064) Bug Fix(es) and Enhancement(s): Getting "build_candidate_list - Database error 11" messages after migrating to LMDB. [rhel-9.8.z] (JIRA:RHEL-152356) Web console doesn't show the sub suffix of ou=foo,ou=people,dc=example,dc=com. [rhel-9.8.z] (JIRA:RHEL-168967) DS 12 does not handle escape char in bind user [rhel-9.8.z] (JIRA:RHEL-170269) [RFE] Add OS-level thread names to all server threads [rhel-9.8.z] (JIRA:RHEL-174524) Online export is failing when using the option "-s" [rhel-9.8.z] (JIRA:RHEL-180716) Server shutdown during online reindex may lead to data loss [rhel-9.8.z] (JIRA:RHEL-183895) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 9 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 x86_64 Red Hat Enterprise Linux for IBM z Systems 9 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.8 s390x Red Hat Enterprise Linux for Power, little endian 9 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.8 ppc64le Red Hat Enterprise Linux for ARM 64 9 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.8 aarch64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.8 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.8 x86_64 Red Hat CodeReady Linux Builder for x86_64 9 x86_64 Red Hat CodeReady Linux Builder for Power, little endian 9 ppc64le Red Hat CodeReady Linux Builder for ARM 64 9 aarch64 Red Hat CodeReady Linux Builder for IBM z Systems 9 s390x Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 9.8 x86_64 Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 9.8 ppc64le Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 9.8 s390x Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 9.8 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.8 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.8 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.8 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.8 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.8 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.8 s390x Fixes BZ - 2480093 - CVE-2026-9064 389-ds-base: 389-ds-base: unbounded LDAP controls count in get_ldapmessage_controls_ext() causes CPU and heap amplification (remote DoS) CVEs CVE-2026-9064 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 9 SRPM 389-ds-base-2.8.0-7.el9_8.src.rpm SHA-256: 1c954eeffa3e0175ab8166aeed60576bbddda1bb0383e07f2d05f584405dbb2d x86_64 389-ds-base-2.8.0-7.el9_8.x86_64.rpm SHA-256: 897f5a48cfc78c68e943ef87829d56b87a7be5978cfa7ba6fafc98a8183d0009 389-ds-base-debuginfo-2.8.0-7.el9_8.x86_64.rpm SHA-256: b72615332ca2ee9d3022ccbcf744a0cddf8eb7b694b2f776b9d2c2c720dac31e 389-ds-base-debugsource-2.8.0-7.el9_8.x86_64.rpm SHA-256: 724b0d4f7ac3d4a8ca31a520e0b1e48b39e28639c74b0042efc43fc6192041f5 389-ds-base-libs-2.8.0-7.el9_8.x86_64.rpm SHA-256: 33ee615217852a0985cbe0e3e3971fa272bef397dde544c796cfd014b786e3c4 389-ds-base-libs-debuginfo-2.8.0-7.el9_8.x86_64.rpm SHA-256: a7dfcee79766f0bda22b89b2a18e3beb27aba5308788d41bf52f78283dff3068 389-ds-base-snmp-2.8.0-7.el9_8.x86_64.rpm SHA-256: 8352e8be9adee26e53b18143b08e282c305ced8161cd9c4820c791ed22f9e5ac 389-ds-base-snmp-debuginfo-2.8.0-7.el9_8.x86_64.rpm SHA-256: 4fad0765851e70d05a05499223c2eeda9e58023059ebc912324cac4c13280c72 python3-lib389-2.8.0-7.el9_8.noarch.rpm SHA-256: 9604c6303a11fcd4b6c52bfb0a2a0aa7121989037feba9137176f74fad18fa03 Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 SRPM 389-ds-base-2.8.0-7.el9_8.src.rpm SHA-256: 1c954eeffa3e0175ab8166aeed60576bbddda1bb0383e07f2d05f584405dbb2d x86_64 389-ds-base-2.8.0-7.el9_8.x86_64.rpm SHA-256: 897f5a48cfc78c68e943ef87829d56b87a7be5978cfa7ba6fafc98a8183d0009 389-ds-base-debuginfo-2.8.0-7.el9_8.x86_64.rpm SHA-256: b72615332ca2ee9d3022ccbcf744a0cddf8eb7b694b2f776b9d2c2c720dac31e 389-ds-base-debugsource-2.8.0-7.el9_8.x86_64.rpm SHA-256: 724b0d4f7ac3d4a8ca31a520e0b1e48b39e28639c74b0042efc43fc6192041f5 389-ds-base-libs-2.8.0-7.el9_8.x86_64.rpm SHA-256: 33ee615217852a0985cbe0e3e3971fa272bef397dde544c796cfd014b786e3c4 389-ds-base-libs-debuginfo-2.8.0-7.el9_8.x86_64.rpm SHA-256: a7dfcee79766f0bda22b89b2a18e3beb27aba5308788d41bf52f78283dff3068 389-ds-base-snmp-2.8.0-7.el9_8.x86_64.rpm SHA-256: 8352e8be9adee26e53b18143b08e282c305ced8161cd9c4820c791ed22f9e5ac 389-ds-base-snmp-debuginfo-2.8.0-7.el9_8.x86_64.rpm SHA-256: 4fad0765851e70d05a05499223c2eeda9e58023059ebc912324cac4c13280c72 python3-lib389-2.8.0-7.el9_8.noarch.rpm SHA-256: 9604c6303a11fcd4b6c52bfb0a2a0aa7121989037feba9137176f74fad18fa03 Red Hat Enterprise Linux for IBM z Systems 9 SRPM 389-ds-base-2.8.0-7.el9_8.src.rpm SHA-256: 1c954eeffa3e0175ab8166aeed60576bbddda1bb0383e07f2d05f584405dbb2d s390x 389-ds-base-2.8.0-7.el9_8.s390x.rpm SHA-256: 9146b5e0dc282cc1283aa5a82f9e9d7f08e6b451a5f97e26bbfaf5d17515c38f 389-ds-base-debuginfo-2.8.0-7.el9_8.s390x.rpm SHA-256: c87732d0d933fa90b8ae4baa94f420d1cdb014f78dee7824bd16abf2ea848f18 389-ds-base-debugsource-2.8.0-7.el9_8.s390x.rpm SHA-256: dc3c5a5824370b56fe91308d25f37179d4d5a45c09366f6cb7a0ccd35580fdc7 389-ds-base-libs-2.8.0-7.el9_8.s390x.rpm SHA-256: eddce7d896eca802c9fb21a444b24a821de86b5e0631ed89149818851f39ee2a 389-ds-base-libs-debuginfo-2.8.0-7.el9_8.s390x.rpm SHA-256: adc75f5e1bc957e6e911e9a35cb4010f62a3842e81c72cab7311c7855e842d78 389-ds-base-snmp-2.8.0-7.el9_8.s390x.rpm SHA-256: 652a9ec6c15a48c3de0ed62f022e1b580d830e359d20872d56dcf9b61595a2f1 389-ds-base-snmp-debuginfo-2.8.0-7.el9_8.s390x.rpm SHA-256: 7cee19a452210244c90a4fe357af16b1cca1d40ff675de9c9fda56e09bb8eb74 python3-lib389-2.8.0-7.el9_8.noarch.rpm SHA-256: 9604c6303a11fcd4b6c52bfb0a2a0aa7121989037feba9137176f74fad18fa03 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.8 SRPM 389-ds-base-2.8.0-7.el9_8.src.rpm SHA-256: 1c954eeffa3e0175ab8166aeed60576bbddda1bb0383e07f2d05f584405dbb2d s390x 389-ds-base-2.8.0-7.el9_8.s390x.rpm SHA-256: 9146b5e0dc282cc1283aa5a82f9e9d7f08e6b451a5f97e26bbfaf5d17515c38f 389-ds-base-debuginfo-2.8.0-7.el9_8.s390x.rpm SHA-256: c87732d0d933fa90b8ae4baa94f420d1cdb014f78dee7824bd16abf2ea848f18 389-ds-base-debugsource-2.8.0-7.el9_8.s390x.rpm SHA-256: dc3c5a5824370b56fe91308d25f37179d4d5a45c09366f6cb7a0ccd35580fdc7 389-ds-base-libs-2.8.0-7.el9_8.s390x.rpm SHA-256: eddce7d896eca802c9fb21a444b24a821de86b5e0631ed89149818851f39ee2a 389-ds-base-libs-debuginfo-2.8.0-7.el9_8.s390x.rpm SHA-256: adc75f5e1bc957e6e911e9a35cb4010f62a3842e81c72cab7311c7855e842d78 389-ds-base-snmp-2.8.0-7.el9_8.s390x.rpm SHA-256: 652a9ec6c15a48c3de0ed62f022e1b580d830e359d20872d56dcf9b61595a2f1 389-ds-base-snmp-debuginfo-2.8.0-7.el9_8.s390x.rpm SHA-256: 7cee19a452210244c90a4fe357af16b1cca1d40ff675de9c9fda56e09bb8eb74 python3-lib389-2.8.0-7.el9_8.noarch.rpm SHA-256: 9604c6303a11fcd4b6c52bfb0a2a0aa7121989037feba9137176f74fad18fa03 Red Hat Enterprise Linux for Power, little endian 9 SRPM 389-ds-base-2.8.0-7.el9_8.src.rpm SHA-256: 1c954eeffa3e0175ab8166aeed60576bbddda1bb0383e07f2d05f584405dbb2d ppc64le 389-ds-base-2.8.0-7.el9_8.ppc64le.rpm SHA-256: a221d1f98e340a8f490344d71598352a407e1119dc305f3ea3065635e4cbd8f7 389-ds-base-debuginfo-2.8.0-7.el9_8.ppc64le.rpm SHA-256: de81004675b5a40034f7359592da9a0738104bbf5669e3abb498cc1df187fa93 389-ds-base-debugsource-2.8.0-7.el9_8.ppc64le.rpm SHA-256: e6ebe6821853f5659bbe215069b9547b75b9d2438674af0bd08fba1167e2a116 389-ds-base-libs-2.8.0-7.el9_8.ppc64le.rpm SHA-256: 6181a3d1586496d16d9ec1f92c9690b9dd0f059a6fa44494d59105e52e7c17c5 389-ds-base-libs-debuginfo-2.8.0-7.el9_8.ppc64le.rpm SHA-256: 0dbe9c19cc59500b0c670884d268608b827a1156463243e384be519fe5a901b9 389-ds-base-snmp-2.8.0-7.el9_8.ppc64le.rpm SHA-256: 36e78f2a71157fc71af2482c93e6d3ab6a4ea75907bce82ade916072fdb0e703 389-ds-base-snmp-debuginfo-2.8.0-7.el9_8.ppc64le.rpm SHA-256: 0c43004ed37cc0c7326a53fdb0efd356861d23b413f75c5e46104364ebc0a8e0 python3-lib389-2.8.0-7.el9_8.noarch.rpm SHA-256: 9604c6303a11fcd4b6c52bfb0a2a0aa7121989037feba9137176f74fad18fa03 Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.8 SRPM 389-ds-base-2.8.0-7.el9_8.src.rpm SHA-256: 1c954eeffa3e0175ab8166aeed60576bbddda1bb0383e07f2d05f584405dbb2d ppc6
A remote denial-of-service vulnerability (CVE-2026-9064, CVSS 7.5 High) in 389-ds-base allows an attacker to cause CPU and heap amplification by sending LDAP messages with an unbounded number of controls. The vulnerability affects Red Hat Directory Server versions 11.0, 12.0, and 13.0, as well as Red Hat Enterprise Linux 6.0. Red Hat has released an update to address this issue; administrators should apply the patch referenced in RHSA-2026:26455 for their specific RHEL 9.x platform.