Red Hat Product Errata RHSA-2026:26463 - Security Advisory Issued: 2026-06-17 Updated: 2026-06-17 RHSA-2026:26463 - Security Advisory Overview Updated Packages Synopsis Important: 389-ds:1.4 security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for the 389-ds:1.4 module is now available for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support and Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description 389 Directory Server is an LDAP version 3 (LDAPv3) compliant server. The base packages include the Lightweight Directory Access Protocol (LDAP) server and command-line utilities for server administration. Security Fix(es): 389-ds-base: 389-ds-base: unbounded LDAP controls count in get_ldapmessage_controls_ext() causes CPU and heap amplification (remote DoS) (CVE-2026-9064) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.4 x86_64 Red Hat Enterprise Linux Server - AUS 8.4 x86_64 Fixes BZ - 2480093 - CVE-2026-9064 389-ds-base: 389-ds-base: unbounded LDAP controls count in get_ldapmessage_controls_ext() causes CPU and heap amplification (remote DoS) CVEs CVE-2026-9064 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.4 SRPM 389-ds-base-1.4.3.34-4.module+el8.4.0+24372+0c6355a1.src.rpm SHA-256: 2c8a70fbff8a578c041078cb22f3adf3e990178e4627be9e45d6141485653031 x86_64 389-ds-base-1.4.3.34-4.module+el8.4.0+24372+0c6355a1.x86_64.rpm SHA-256: df32286dac4e0136c3516a9ac5693e11ab84e4f890bb1d17fc2827ae849361a3 389-ds-base-debuginfo-1.4.3.34-4.module+el8.4.0+24372+0c6355a1.x86_64.rpm SHA-256: cf3d50034d43ac352acb0785bd7e1487e630579c8df0bbb2231f0f8a1dc11fd8 389-ds-base-debugsource-1.4.3.34-4.module+el8.4.0+24372+0c6355a1.x86_64.rpm SHA-256: be0c50334b6c611113c13cd627c73e227069ad14ef3757fb214aa213a561fa33 389-ds-base-devel-1.4.3.34-4.module+el8.4.0+24372+0c6355a1.x86_64.rpm SHA-256: 532305104308668197cf113ddde6f317244b7b83b072094213a993a239833f42 389-ds-base-legacy-tools-1.4.3.34-4.module+el8.4.0+24372+0c6355a1.x86_64.rpm SHA-256: 0406e43ce0a90f67557fffbb5ad716a446f6d4211dfcdfc6100b6b3d0662eed5 389-ds-base-legacy-tools-debuginfo-1.4.3.34-4.module+el8.4.0+24372+0c6355a1.x86_64.rpm SHA-256: 7e339463919c120cfce62e7be732e370bd48a5d3564e5181b17410802374e2ba 389-ds-base-libs-1.4.3.34-4.module+el8.4.0+24372+0c6355a1.x86_64.rpm SHA-256: 664d92608ba751171cd8d450a32131644b36610f8a618e9f6dda77ae756dd36b 389-ds-base-libs-debuginfo-1.4.3.34-4.module+el8.4.0+24372+0c6355a1.x86_64.rpm SHA-256: 778ad8202a26faca0d0fe856cca84cf0478bc6cd4c97c1c84c2ce01cf14caabe 389-ds-base-snmp-1.4.3.34-4.module+el8.4.0+24372+0c6355a1.x86_64.rpm SHA-256: a9a82720cda39626f9e166e59723f0959a94d1b5404a3724a27af6c3f6c79a69 389-ds-base-snmp-debuginfo-1.4.3.34-4.module+el8.4.0+24372+0c6355a1.x86_64.rpm SHA-256: ece688becbdd775bc9a6714da21df0b9daa99a1277a79066167d52256f792b22 python3-lib389-1.4.3.34-4.module+el8.4.0+24372+0c6355a1.noarch.rpm SHA-256: 30a87a9ced26ab876447a220cc16ad486080a1a738cd1b3815c81316e5075c29 Red Hat Enterprise Linux Server - AUS 8.4 SRPM 389-ds-base-1.4.3.34-4.module+el8.4.0+24372+0c6355a1.src.rpm SHA-256: 2c8a70fbff8a578c041078cb22f3adf3e990178e4627be9e45d6141485653031 x86_64 389-ds-base-1.4.3.34-4.module+el8.4.0+24372+0c6355a1.x86_64.rpm SHA-256: df32286dac4e0136c3516a9ac5693e11ab84e4f890bb1d17fc2827ae849361a3 389-ds-base-debuginfo-1.4.3.34-4.module+el8.4.0+24372+0c6355a1.x86_64.rpm SHA-256: cf3d50034d43ac352acb0785bd7e1487e630579c8df0bbb2231f0f8a1dc11fd8 389-ds-base-debugsource-1.4.3.34-4.module+el8.4.0+24372+0c6355a1.x86_64.rpm SHA-256: be0c50334b6c611113c13cd627c73e227069ad14ef3757fb214aa213a561fa33 389-ds-base-devel-1.4.3.34-4.module+el8.4.0+24372+0c6355a1.x86_64.rpm SHA-256: 532305104308668197cf113ddde6f317244b7b83b072094213a993a239833f42 389-ds-base-legacy-tools-1.4.3.34-4.module+el8.4.0+24372+0c6355a1.x86_64.rpm SHA-256: 0406e43ce0a90f67557fffbb5ad716a446f6d4211dfcdfc6100b6b3d0662eed5 389-ds-base-legacy-tools-debuginfo-1.4.3.34-4.module+el8.4.0+24372+0c6355a1.x86_64.rpm SHA-256: 7e339463919c120cfce62e7be732e370bd48a5d3564e5181b17410802374e2ba 389-ds-base-libs-1.4.3.34-4.module+el8.4.0+24372+0c6355a1.x86_64.rpm SHA-256: 664d92608ba751171cd8d450a32131644b36610f8a618e9f6dda77ae756dd36b 389-ds-base-libs-debuginfo-1.4.3.34-4.module+el8.4.0+24372+0c6355a1.x86_64.rpm SHA-256: 778ad8202a26faca0d0fe856cca84cf0478bc6cd4c97c1c84c2ce01cf14caabe 389-ds-base-snmp-1.4.3.34-4.module+el8.4.0+24372+0c6355a1.x86_64.rpm SHA-256: a9a82720cda39626f9e166e59723f0959a94d1b5404a3724a27af6c3f6c79a69 389-ds-base-snmp-debuginfo-1.4.3.34-4.module+el8.4.0+24372+0c6355a1.x86_64.rpm SHA-256: ece688becbdd775bc9a6714da21df0b9daa99a1277a79066167d52256f792b22 python3-lib389-1.4.3.34-4.module+el8.4.0+24372+0c6355a1.noarch.rpm SHA-256: 30a87a9ced26ab876447a220cc16ad486080a1a738cd1b3815c81316e5075c29 The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .
A remote denial-of-service vulnerability (CVE-2026-9064, CVSS 7.5 HIGH) exists in 389-ds-base where an attacker can cause excessive CPU and heap consumption by sending an LDAP message with an unbounded number of LDAP controls. The vulnerability affects Red Hat Directory Server versions 11.0, 12.0, and 13.0, as well as Red Hat Enterprise Linux 6.0. The advisory provides updated packages for the 389-ds:1.4 module on RHEL 8.4, specifically version 389-ds-base-1.4.3.34-4.