This update for 389-ds fixes the following issue
- CVE-2026-9064: unbounded LDAP controls count in `get_ldapmessage_controls_ext()` can lead to amplified CPU time and
heap allocation and a denial of service (bsc#1265898).
Changes for 389-ds:
- Update to version 3.0.6~git337.647f49042:
* Issue 7541 - heap-buffer-overflows in __aclp__normalize_acltxt() (#7542)
* Issue 7531 - Fix LMDB replication regression_m2 failures and core dumps (#7575)
* Issue 7496 - fix cherry-pick error
* Issue 7490 - Enable USDT probes by default in RPM (#7491)
* Issue 7576 - Fix leak of temporary attribute syntax hash tables after schema reload
* Issue 7558 - During online import, the IDL should be created with in-depth first approach (#7559)
* Issue 7500 - Prevent unsigned integer underflow during stalled import
* Issue 7562 - Error: NssSsl.add_cert() got an unexpected keyword argument 'input_file' (#7563)
* Issue 7560 - lib389 - Add helper function for checking ASAN files
* Issue 7539 - Server...
Read the Full Advisory- openSUSE Leap 16.0:
389-ds-3.0.6~git337.647f49042-160000.1.1
389-ds-devel-3.0.6~git337.647f49042-160000.1.1
389-ds-snmp-3.0.6~git337.647f49042-160000.1.1
lib389-3.0.6~git337.647f49042-160000.1.1
libsvrcore0-3.0.6~git337.647f49042-160000.1.1
* bsc#1265898
References:
* https://www.suse.com/security/cve/CVE-2026-9064.html
Get the latest Linux and open source security news straight to your inbox.