-
Fri Jun 26 2026 Viktor Ashirov <vashirov@redhat.com> - 3.2.0-8
- Bump version to 3.2.0-8
- Resolves: RHEL-182152 - CVE-2026-11610 389-ds-base: 389-ds-base: Heap
buffer overflow in sasl_io_recv() via padded SASL UNBIND [rhel-10.2.z]
- Resolves: RHEL-183105 - CVE-2026-11774 389-ds-base: 389-ds-base: integer
overflow in SASL packet length bypasses size limit leading to heap buffer
overflow [rhel-10.2.z]
-
Thu Jun 11 2026 Viktor Ashirov <vashirov@redhat.com> - 3.2.0-7
- Bump version to 3.2.0-7
- Resolves: RHEL-170271 - DS 12 does not handle escape char in bind user
[rhel-10.2.z]
- Resolves: RHEL-170276 - dnaSharedConfig: "dnaPortNum: 0" [rhel-10.2.z]
- Resolves: RHEL-170281 - Memory leaks in syncrepl plugin during persistent
search operations [rhel-10.2.z]
- Resolves: RHEL-170363 - access log - suspicious wtime optime negative
and large values in internal op [rhel-10.2.z]
- Resolves: RHEL-170478 - An online reinitialization with LMDB is
terminating the receiving server [rhel-10.2.z]
- Resolves: RHEL-170481 - dsctl healthcheck DSMOLE0001 inaccurate
recommendations when there is more than 1 LDAP backend [rhel-10.2.z]
- Resolves: RHEL-170515 - Possible memory leak when using the Retro
Changelog plugin. [rhel-10.2.z]
- Resolves: RHEL-174526 - [RFE] Add OS-level thread names to all server
threads [rhel-10.2.z]
- Resolves: RHEL-178074 - CVE-2026-9064 389-ds-base: 389-ds-base: unbounded
LDAP controls count in get_ldapmessage_controls_ext() causes CPU and heap
amplification (remote DoS) [rhel-10.2]
- Resolves: RHEL-180718 - Online export is failing when using the option
"-s" [rhel-10.2.z]
- Resolves: RHEL-183897 - Server shutdown during online reindex may lead to
data loss [rhel-10.2.z]
- Resolves: RHEL-183898 - Error: NssSsl.add_cert() got an unexpected
keyword argument 'input_file' [rhel-10.2.z]
- Resolves: RHEL-183899 - Replication errors in logs [rhel-10.2.z]
- Resolves: RHEL-183900 - Substring index produces empty results and can
crash when non-default nsSubStrBegin/nsSubStrEnd lengths are configured
[rhel-10.2.z]
-
Thu Mar 05 2026 Viktor Ashirov <vashirov@redhat.com> - 3.2.0-6
- Bump version to 3.2.0-6
- Resolves: RHEL-86312 - Crash in trim_changelog() during the Retro
Changelog trimming.
-
Sat Feb 28 2026 Viktor Ashirov <vashirov@redhat.com> - 3.2.0-5
- Bump version to 3.2.0-5
-
Fri Feb 27 2026 Viktor Ashirov <vashirov@redhat.com> - 3.2.0-4
- Bump version to 3.2.0-4
- Resolves: RHEL-86312 - Crash in trim_changelog() during the Retro
Changelog trimming.
- Resolves: RHEL-133085 - Replica installation is failing with message
MDB_BAD_VALSIZE: Unsupported size of key/DB name/data, or wrong DUPFIXED
- Resolves: RHEL-137072 - CVE-2025-14905 389-ds-base: 389-ds-base: Remote
Code Execution and Denial of Service via heap buffer overflow [rhel-10.2]
- Resolves: RHEL-138729 - Crash ( Segmentation fault ) in
atomic_compare_exchange()
-
Fri Feb 20 2026 Viktor Ashirov <vashirov@redhat.com> - 3.2.0-3
- Bump version to 3.2.0-3
- Resolves: RHEL-76835 - Web console doesn't show the sub suffix of
ou=foo,ou=people,dc=example,dc=com.
- Resolves: RHEL-86320 - [RFE] Support updating/renewing TLS certificate
without restarting slapd
- Resolves: RHEL-110192 - ns-slapd doesn't support PQC keys
- Resolves: RHEL-111220 - RHDS-11.9 dsctl db2index --attr recreates all
indexes instead of selected ones
- Resolves: RHEL-111931 - Improve error messages for dsconf localpwp list
- Resolves: RHEL-121981 - Setting password history count to 0 does not
flush history
- Resolves: RHEL-122625 - ipa-healthcheck is complaining about missing or
incorrectly configured system indexes.
- Resolves: RHEL-128906 - Scalability issue of replication online
initialization with large database
- Resolves: RHEL-137786 - Upgrading IDM to latest version: 389-ds-base and
ipa-server breaks replication
- Resolves: RHEL-146769 - Remove memberof_del_dn_from_groups from MemberOf
plugin
-
Mon Jan 12 2026 Viktor Ashirov <vashirov@redhat.com> - 3.2.0-2
- Resolves: RHEL-137786 - Upgrading IDM to latest version: 389-ds-base and
ipa-server breaks replication
-
Thu Jan 08 2026 Viktor Ashirov <vashirov@redhat.com> - 3.2.0-1
- Update to 3.2.0
- Resolves: RHEL-18041 - [RFE] When there are multiple backends cache auto-
tune should adapt its tuning
- Resolves: RHEL-58682 - [RFE] modify entry cache eviction strategy to
allow large groups to stay in the cache
- Resolves: RHEL-64019 - Units for changing MDB max size are not consistent
across different tools
- Resolves: RHEL-83274 - Replication online reinitialization of a large
database gets stalled.
- Resolves: RHEL-83852 - LDAP high CPU usage while handling indexes with
IDL scan limit at INT_MAX
- Resolves: RHEL-86534 - [RFE] Support Dynamic Groups similar to OpenLDAP
- Resolves: RHEL-89601 - (&(cn:dn:=groups)) no longer returns results
- Resolves: RHEL-94025 - PAM Pass Through Authentication Plugin processes
requests for accounts that do not meet the criteria specified in the
`pamFilter` option.
- Resolves: RHEL-95395 - Getting "build_candidate_list - Database error 11"
messages after migrating to LMDB.
- Resolves: RHEL-96196 - Duplicate/double local password policy entry
display from redhat directory server webconsole
- Resolves: RHEL-99331 - [RFE] Need an option with dsconf to delete all the
conflicts at once instead of deleting each conflict one after the other
- Resolves: RHEL-105578 - IPA health check up script shows time skew is
over 24 hours
- Resolves: RHEL-106502 - Ignore the memberOfDeferredUpdate setting when
LMDB is used.
- Resolves: RHEL-106559 - When deferred memberof update is enabled after
the server crashed it should not launch memberof fixup task by default
- Resolves: RHEL-106849 - Abort the offline import if the root entry cannot
be added.
- Resolves: RHEL-107003 - Improve output dsctl dbverify when backend does
not exist
- Resolves: RHEL-109113 - [RFE] memberOf plugin - Add scope for specific
groups
- Resolves: RHEL-111219 - Attribute uniqueness is not enforced upon modrdn
operation
- Resolves: RHEL-113965 - RetroCL plugin generates invalid LDIF
- Resolves: RHEL-115179 - Several password related attributes are not
replicating from the Replicas to the Masters
- Resolves: RHEL-115484 - ns-slapd crash in libdb, possible memory
corruption
- Resolves: RHEL-116060 - Fix paged result search locking
- Resolves: RHEL-117124 - Missing access JSON logging for TLS/CLient auth
- Resolves: RHEL-117140 - Changelog trimming - add number of scanned
entries to the log
- Resolves: RHEL-117520 - Typo in errors log after a Memberof fixup task.
- Resolves: RHEL-121208 - [RFE] Make nsslapd-haproxy-trusted-ip accept
whole subnets
- Resolves: RHEL-122625 - ipa-healthcheck is complaining about missing or
incorrectly configured system indexes.
- Resolves: RHEL-122674 - [WebUI] Replication tab crashes after enabling
replication as a consumer
- Resolves: RHEL-123220 - Improve the way to detect asynchronous operations
in the access logs
- Resolves: RHEL-123275 - The new ipahealthcheck test
ipahealthcheck.ds.backends.BackendsCheck raises CRITICAL issue
- Resolves: RHEL-123663 - Online initialization of consumers fails with
error -23
- Resolves: RHEL-123664 - RHDS 12.6 doesn't handle 'ldapsearch' filter with
space char in DN name correctly
- Resolves: RHEL-123762 - 389-ds-base OpenScanHub Leaks Detected
- Resolves: RHEL-124694 - Access logs are not getting deleted as
configured.
- Resolves: RHEL-126535 - memory corruption in alias entry plugin
- Resolves: RHEL-128906 - Scalability issue of replication online
initialization with large database
- Resolves: RHEL-129675 - Can't locate CSN error seen in errors log when
replicating after importing data from ldif files
- Resolves: RHEL-131129 - ns-slapd[2233]: segfault at 0 ip 00007f1f1d7cd7fc
sp 00007f1e775fc070 error 4 in libjemalloc.so.2[7f1f1d738000+ac000] on
389-ds-base-2.6.1-11
- Resolves: RHEL-133795 - Memory leak observed in ns-slapd with 389-ds-
base-2.6.1-12
- Resolves: RHEL-139826 - Rebase 389-ds-base to 3.2.x
-
Thu Sep 18 2025 Viktor Ashirov <vashirov@redhat.com> - 3.1.3-5
- Resolves: RHEL-101727 - The numSubordinates value is not matching the
number of direct children.
- Resolves: RHEL-101783 - RHDS12: Web console doesn't show Server Version
- Resolves: RHEL-109018 - Allow Uniqueness plugin to search uniqueness
attributes using custom matching rules
- Resolves: RHEL-111224 - Error showing local password policy on web UI
- Resolves: RHEL-112675 - Statistics about index lookup report a wrong
duration
- Resolves: RHEL-112689 - Crash if repl keep alive entry can not be created
- Resolves: RHEL-112722 - Exception thrown by dsconf instance repl get_ruv
- Resolves: RHEL-113969 - AddressSanitizer: memory leak in
memberof_add_memberof_attr
-
Tue Aug 05 2025 Viktor Ashirov <vashirov@redhat.com> - 3.1.3-4
- Resolves: RHEL-73032 - segfault - error 4 in libpthread-2.28.so
- Resolves: RHEL-79079 - Failure to get Server monitoring data when NDN
cache is disabled.
- Resolves: RHEL-87352 - ns-slapd crashed when we add nsslapd-referral
- Resolves: RHEL-92054 - Memory leak in
roles_cache_create_object_from_entry [rhel-10]
- Resolves: RHEL-107001 - ipa-restore fails to restore SELinux contexts,
causes ns-slapd AVC denials on /dev/shm after restore. [rhel-10]
- Resolves: RHEL-107028 - CWE-284 dirsrv log rotation creates files with
world readable permission
- Resolves: RHEL-107035 - CWE-532 Created user password hash available to
see in audit log
- Resolves: RHEL-107037 - CWE-778 Log doesn't show what user gets password
changed by administrator