Alerts This Week
Warning Icon 1 1,365
Alerts This Week
Warning Icon 1 1,365

openSUSE 389-ds Important Denial of Service Fix CVE-2026-9064 2026-21011-1

opensuse
Calendar Grey June 30, 2026
Dist Opensuse Esm H88
Update for 389-ds addresses denial of service issue; important fixes and updates applicable now.
An update that solves one vulnerability and has one bug fix can now be installed.

Description

This update for 389-ds fixes the following issue

- CVE-2026-9064: unbounded LDAP controls count in `get_ldapmessage_controls_ext()` can lead to amplified CPU time and

heap allocation and a denial of service (bsc#1265898).

Changes for 389-ds:

- Update to version 3.0.6~git337.647f49042:

* Issue 7541 - heap-buffer-overflows in __aclp__normalize_acltxt() (#7542)

* Issue 7531 - Fix LMDB replication regression_m2 failures and core dumps (#7575)

* Issue 7496 - fix cherry-pick error

* Issue 7490 - Enable USDT probes by default in RPM (#7491)

* Issue 7576 - Fix leak of temporary attribute syntax hash tables after schema reload

* Issue 7558 - During online import, the IDL should be created with in-depth first approach (#7559)

* Issue 7500 - Prevent unsigned integer underflow during stalled import

* Issue 7562 - Error: NssSsl.add_cert() got an unexpected keyword argument 'input_file' (#7563)

* Issue 7560 - lib389 - Add helper function for checking ASAN files

* Issue 7539 - Server...

Read the Full Advisory

Patch

Package List

- openSUSE Leap 16.0:

389-ds-3.0.6~git337.647f49042-160000.1.1

389-ds-devel-3.0.6~git337.647f49042-160000.1.1

389-ds-snmp-3.0.6~git337.647f49042-160000.1.1

lib389-3.0.6~git337.647f49042-160000.1.1

libsvrcore0-3.0.6~git337.647f49042-160000.1.1

References

* bsc#1265898

References:

* https://www.suse.com/security/cve/CVE-2026-9064.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2026:21011-1
Rating: important
Affected Products: openSUSE Leap 16.0 -------------------------------------------------------------

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here