Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:36204: Important: redhat-ds:11 security update

This Important update for Red Hat Directory Server 11.5 E4S on RHEL 8 addresses two high-severity heap buffer overflows (CVE-2026-11610, CVSS 8.8, and CVE-2026-11774, CVSS 7.6) in the 389-ds-base component, which can be exploited via crafted SASL packets to cause integer overflows and memory corruption. The vulnerabilities affect the 389-ds-base package version 1.4.3.34-7 and are resolved in the updated packages provided in the advisory, such as 389-ds-base-1.4.3.34-7.module+el8dsrv+24471+245dd8e2.x86_64.rpm.
Read Full Article →

Red Hat Product Errata RHSA-2026:36204 - Security Advisory Issued: 2026-07-07 Updated: 2026-07-07 RHSA-2026:36204 - Security Advisory Overview Updated Packages Synopsis Important: redhat-ds:11 security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for the redhat-ds:11 module is now available for Red Hat Directory Server 11.5 E4S for RHEL 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Red Hat Directory Server is an LDAPv3-compliant directory server. The suite of packages includes the Lightweight Directory Access Protocol (LDAP) server, as well as command-line utilities and Web UI packages for server administration. Security Fix(es): 389-ds-base: 389-ds-base: Heap buffer overflow in sasl_io_recv() via padded SASL UNBIND (CVE-2026-11610) 389-ds-base: 389-ds-base: integer overflow in SASL packet length bypasses size limit leading to heap buffer overflow (CVE-2026-11774) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Directory Server - 4 years of updates 11 for RHEL 8.6 x86_64 Fixes BZ - 2484414 - CVE-2026-11610 389-ds-base: 389-ds-base: Heap buffer overflow in sasl_io_recv() via padded SASL UNBIND BZ - 2484916 - CVE-2026-11774 389-ds-base: 389-ds-base: integer overflow in SASL packet length bypasses size limit leading to heap buffer overflow CVEs CVE-2026-11610 CVE-2026-11774 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Directory Server - 4 years of updates 11 for RHEL 8.6 SRPM 389-ds-base-1.4.3.34-7.module+el8dsrv+24471+245dd8e2.src.rpm SHA-256: 119240adc36d4cac4a362f5f928b4e7af9e4418e19ceb0708809f6b580c10488 x86_64 389-ds-base-1.4.3.34-7.module+el8dsrv+24471+245dd8e2.x86_64.rpm SHA-256: d83611b89952dd36977ccaca1e4ed63b8705d3bdee370e6c99f8da851d46c067 389-ds-base-debuginfo-1.4.3.34-7.module+el8dsrv+24471+245dd8e2.x86_64.rpm SHA-256: ce162d52c8483e64cc0f44f8066a388d4d1747101329161adeb226dd2fd59203 389-ds-base-debugsource-1.4.3.34-7.module+el8dsrv+24471+245dd8e2.x86_64.rpm SHA-256: 3df3037837f630a8d63d301883213002b70f7905211f28efb937f433fc877dd0 389-ds-base-devel-1.4.3.34-7.module+el8dsrv+24471+245dd8e2.x86_64.rpm SHA-256: 25fe78dcdb99181329fb2ba550dd6bcc0e0afc301cc5acf6cdab2a20b1d4fe5f 389-ds-base-legacy-tools-1.4.3.34-7.module+el8dsrv+24471+245dd8e2.x86_64.rpm SHA-256: d40ef92cc40a1dc7a9fd1c2c6e630e7824e9ffdd5f33c4aee73c8c4e53a01c62 389-ds-base-legacy-tools-debuginfo-1.4.3.34-7.module+el8dsrv+24471+245dd8e2.x86_64.rpm SHA-256: 245f01cd1b6d85a84d4ce3713d620abae23edfcbb01c893f6ab67b0358d6344f 389-ds-base-libs-1.4.3.34-7.module+el8dsrv+24471+245dd8e2.x86_64.rpm SHA-256: bbc05a265bff9921d7e2e2fa8e5883a4369a17fd1b117baf8539ac21f13243aa 389-ds-base-libs-debuginfo-1.4.3.34-7.module+el8dsrv+24471+245dd8e2.x86_64.rpm SHA-256: 907e5bf3035d6c0e3c6f8a762c7f06f1776fc374bc144ae789545cbd3197c725 389-ds-base-snmp-1.4.3.34-7.module+el8dsrv+24471+245dd8e2.x86_64.rpm SHA-256: 8a05efdf9100febe1b1005563e17387488439a26e6e48a5d73a04271e6450cbd 389-ds-base-snmp-debuginfo-1.4.3.34-7.module+el8dsrv+24471+245dd8e2.x86_64.rpm SHA-256: b80adc9bf0f86f76e9a4d17ec21c2af9f5b63f011878c10e8b7b4e593ecb200b cockpit-389-ds-1.4.3.34-7.module+el8dsrv+24471+245dd8e2.noarch.rpm SHA-256: 2ceb51059150098881bd6a8cadda8b8fbf6f8a7b5abc90fa9282731c3888dd86 python3-lib389-1.4.3.34-7.module+el8dsrv+24471+245dd8e2.noarch.rpm SHA-256: 791b1a2be2f972b84395830b484813b253510a964529baf242b6b3b976f5094b The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .

Share this article