RHSA-2026:36205: Important: 389-ds-base security update
389 Directory Server is an LDAP version 3 (LDAPv3) compliant server. The base packages include the Lightweight Directory Access Protocol (LDAP) server and command-line utilities for server administration.Security Fix(es): 389-ds-base: 389-ds-base: Heap buffer overflow in sasliorecv() via padded SASL UNBIND (CVE-2026-11610) 389-ds-base: 389-ds-base: integer overflow in SASL packet length bypasses size limit leading to heap buffer overflow (CVE-2026-11774) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/389-ds-baseto a version that resolves this vulnerability.Fixed in 1.3.11.1-13.el7_9 - Upgrade
Upgrade
redhat/389-ds-base-debuginfoto a version that resolves this vulnerability.Fixed in 1.3.11.1-13.el7_9 - Upgrade
Upgrade
redhat/389-ds-base-develto a version that resolves this vulnerability.Fixed in 1.3.11.1-13.el7_9 - Upgrade
Upgrade
redhat/389-ds-base-libsto a version that resolves this vulnerability.Fixed in 1.3.11.1-13.el7_9 - Upgrade
Upgrade
redhat/389-ds-base-snmpto a version that resolves this vulnerability.Fixed in 1.3.11.1-13.el7_9 - Upgrade
Upgrade
389-ds-baseto a version that resolves this vulnerability.Patch CVE-2026-11774 - Upgrade
Upgrade
389-ds-baseto a version that resolves this vulnerability.Patch CVE-2026-11610
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:36205?
The severity of RHSA-2026:36205 is high, rated at 7.
What does RHSA-2026:36205 address?
RHSA-2026:36205 addresses important security updates for the 389-ds-base software.
How do I fix RHSA-2026:36205?
To fix RHSA-2026:36205, apply the recommended security updates provided by Red Hat.
Which software is affected by RHSA-2026:36205?
RHSA-2026:36205 affects various versions of Red Hat Enterprise Linux Server under Extended Life Cycle Support.
When was RHSA-2026:36205 published?
RHSA-2026:36205 was published on July 7, 2026.