| Name: | 389-ds-base |
| Version: | 1.4.3.39 |
| Release: | 28.module+el8.10.0+91024+7bf29691 |
| Architecture: | aarch64 |
| Module: | 389-ds:1.4:8100020260904155442:1f29b1c5
|
| Group: | System Environment/Daemons |
| Size: | 12602367 |
| License: | GPL-3.0-or-later WITH GPL-3.0-389-ds-base-exception AND (0BSD OR Apache-2.0 OR MIT) AND (Apache-2.0 OR Apache-2.0 WITH LLVM-exception OR MIT) AND (Apache-2.0 OR BSD-2-Clause OR MIT) AND (Apache-2.0 OR BSL-1.0) AND (Apache-2.0 OR LGPL-2.1-or-later OR MIT) AND (Apache-2.0 OR MIT OR Zlib) AND (Apache-2.0 OR MIT) AND (MIT OR Apache-2.0) AND Unicode-3.0 AND (MIT OR Unlicense) AND Apache-2.0 AND BSD-3-Clause AND MIT AND MPL-2.0 |
| RPM: |
389-ds-base-1.4.3.39-28.module+el8.10.0+91024+7bf29691.aarch64.rpm
|
| Source RPM: |
389-ds-base-1.4.3.39-28.module+el8.10.0+91024+7bf29691.src.rpm
|
| Build Date: | Wed Sep 09 2026 |
| Build Host: | build-ol8-aarch64.oracle.com |
| Vendor: | Oracle America |
| URL: | https://www.port389.org |
| Summary: | 389 Directory Server (base) |
| Description: | 389 Directory Server is an LDAPv3 compliant server. The base package includes
the LDAP server and command line utilities for server administration. |
-
Fri Sep 04 2026 Anuar Beisembayev <abeisemb@redhat.com> - 1.4.3.39-28
- Bump version to 1.4.3.39-28
- Resolves: RHEL-222326 - EMBARGOED CVE-2026-18453 389-ds:1.4/389-ds-base: 389-ds-base: pre-authentication NULL pointer dereference via paged results and USE_ONE_BACKEND control in op_shared_search [rhel-8.10.z]
- Resolves: RHEL-220511 - EMBARGOED CVE-2026-18355 389-ds:1.4/389-ds-base: 389-ds-base: heap buffer overflow via SASL wrapped-record length lower-bound underflow in sasl_io_start_packet() [rhel-8.10.z]
- Resolves: RHEL-232864 - EMBARGOED CVE-2026-18922 389-ds:1.4/389-ds-base: 389-ds-base: SASL PLAIN authentication allows privilege escalation to Directory Manager via stale identity in Cyrus SASL auxiliary property [rhel-8.10.z]
- Resolves: RHEL-244463 - lib389: set nsDS5ReplicaBindDNGroup before ensure_agreement() [rhel-8.10.z]
- Resolves: RHEL-245383 - EMBARGOED CVE-2026-76560 389-ds-base: 389-ds: anonymous LDAP client can defeat SELFDN ACI bind-rule checks via empty bind DN [rhel-8.10.z]
- Resolves: RHEL-248762 - CVE-2026-11770 fix breaks replication total init when nsDS5ReplicaBindDNGroup is set after agreement creation [rhel-8.10.z]
-
Tue Aug 25 2026 Anuar Beisembayev <abeisemb@redhat.com> - 1.4.3.39-27
- Bump version to 1.4.3.39-27
- Resolves: RHEL-222326 - EMBARGOED CVE-2026-18453 389-ds:1.4/389-ds-base: 389-ds-base: pre-authentication NULL pointer dereference via paged results and USE_ONE_BACKEND control in op_shared_search [rhel-8.10.z]
- Resolves: RHEL-220511 - EMBARGOED CVE-2026-18355 389-ds:1.4/389-ds-base: 389-ds-base: heap buffer overflow via SASL wrapped-record length lower-bound underflow in sasl_io_start_packet() [rhel-8.10.z]
- Resolves: RHEL-232864 - EMBARGOED CVE-2026-18922 389-ds:1.4/389-ds-base: 389-ds-base: SASL PLAIN authentication allows privilege escalation to Directory Manager via stale identity in Cyrus SASL auxiliary property [rhel-8.10.z]
- Resolves: RHEL-244463 - lib389: set nsDS5ReplicaBindDNGroup before ensure_agreement() [rhel-8.10.z]
- Resolves: RHEL-245383 - EMBARGOED CVE-2026-76560 389-ds-base: 389-ds: anonymous LDAP client can defeat SELFDN ACI bind-rule checks via empty bind DN [rhel-8.10.z]
- Resolves: RHEL-248762 - CVE-2026-11770 fix breaks replication total init when nsDS5ReplicaBindDNGroup is set after agreement creation [rhel-8.10.z]
-
Mon Jul 27 2026 Anuar Beisembayev <abeisemb@redhat.com> - 1.4.3.39-26
- Bump version to 1.4.3.39-26
- Resolves: RHEL-183073 - EMBARGOED CVE-2026-11770 389-ds-base: 389-ds-base: pre-auth LDAP filter injection in CleanAllRUV status check [rhel-8.10.z]
- Resolves: RHEL-190782 - CVE-2026-11788 389-ds-base: 389-ds-base: NULL pointer dereference in deref control plugin BER parser [rhel-8.10.z]
- Resolves: RHEL-210880 - EMBARGOED CVE-2026-15722 389-ds:1.4/389-ds-base: 389-ds-base: pre-authentication stack buffer overflow in get_ruvelement_from_berval() via unbounded replica ID parsing [rhel-8.10.z]
-
Thu Jun 25 2026 Anuar Beisembayev <abeisemb@redhat.com> - 1.4.3.39-25
- Bump version to 1.4.3.39-25
- Resolves: RHEL-182162 - EMBARGOED CVE-2026-11610 389-ds-base: 389-ds-base: Heap buffer overflow in sasl_io_recv() via padded SASL UNBIND [rhel-8.10.z]
- Resolves: RHEL-183102 - CVE-2026-11774 389-ds-base: 389-ds-base: integer overflow in SASL packet length bypasses size limit
-
Wed May 13 2026 Arun Bansal <arbansal@redhat.com> - 1.4.3.39-24
- Bump version to 1.4.3.39-24
- Resolves: RHEL-170278 - Memory leaks in syncrepl plugin during persistent search operations [rhel-8.10.z]
- Resolves: RHEL-163375 - WARN - keys2idl - received NULL idl from index_read_ext_allids
- Resolves: RHEL-159306 - ns-slapd crash in libdb possible memory corruption [rhel-8.10.z]
- Resolves: RHEL-170284 - access log - suspicious wtime optime negative and large values in internal op [rhel-8.10.z]
- Resolves: RHEL-170507 - ns-slapd fails to shutdown when deferred memberof update is in progress [rhel-8.10.z]
- Resolves: RHEL-170509 - Crash in trim_changelog() during the Retro Changelog trimming [rhel-8.10.z]
- Resolves: RHEL-170514 - Possible memory leak when using the Retro Changelog plugin [rhel-8.10.z]
- Resolves: RHEL-170512 - Crash in replica_config_add when manually configuring a replica with an incorrect nsds5ReplicaRoot [rhel-8.10.z]
- Resolves: RHEL-174523 - [RFE] Add OS-level thread names to all server threads [rhel-8.10.z]
- Resolves: RHEL-170483 - test_vlv_recreation_reindex fails on LMDB [rhel-8.10.z]
- Resolves: RHEL-178076 - CVE-2026-9064 389-ds:1.4/389-ds-base: unbounded LDAP controls count in get_ldapmessage_controls_ext() causes CPU and heap amplification (remote DoS) [rhel-8.10.z]
-
Wed Mar 04 2026 Arun Bansal <arbansal@redhat.com> - 1.4.3.39-23
- Resolves: RHEL-137074 - CVE-2025-14905 389-ds:1.4/389-ds-base: 389-ds-base: Remote Code Execution and Denial of Service via heap buffer overflow [rhel-8.10.z]
- Resolves: RHEL-152098 - Scalability issue of replication online initialization with large database [rhel-8.10.z]
-
Wed Feb 18 2026 Viktor Ashirov <vashirov@redhat.com> - 1.4.3.39-22
- Resolves: RHEL-148485 - Upgrading IDM to latest version: 389-ds-base and ipa-server breaks replication [rhel-8.10.z]
-
Fri Jan 23 2026 Arun Bansal <arbansal@redhat.com> - 1.4.3.39-21
- Resolves: RHEL-141419 - (&(cn:dn:=groups)) no longer returns results [rhel-8.10.z]
- Resolves: RHEL-140272 - ipa-healthcheck is complaining about missing or
incorrectly configured system indexes. [rhel-8.10.z]
-
Tue Jan 13 2026 Arun Bansal <arbansal@redhat.com> - 1.4.3.39-20
- Resolves: RHEL-140086 - Upgrading IDM to latest version: 389-ds-base and ipa-server breaks replication [rhel-8.10.z]
-
Fri Dec 05 2025 Masahiro Matsuya <mmatsuya@redhat.com> - 1.4.3.39-19
- Resolves: RHEL-117759 - Replication online reinitialization of a large database gets stalled. [rhel-8.10.z]