RHSA-2026:56050: Important: redhat-ds:12 security update
Important: redhat-ds:12 security update
Other sources
Red Hat Directory Server is an LDAPv3-compliant directory server. The suite of packages includes the Lightweight Directory Access Protocol (LDAP) server, as well as command-line utilities and Web UI packages for server administration.Security Fix(es): 389-ds-base: 389-ds-base: pre-auth LDAP filter injection in CleanAllRUV status check (CVE-2026-11770) 389-ds-base: 389-ds-base: NULL pointer dereference in deref control plugin BER parser (CVE-2026-11788) 389-ds-base: 389-ds-base: pre-authentication stack buffer overflow in getruvelementfromberval() via unbounded replica ID parsing (CVE-2026-15722) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/389-ds-baseto a version that resolves this vulnerability.Fixed in 2.4.5-25.module+el9d - Upgrade
Upgrade
redhat/389-ds-base-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.5-25.module+el9d - Upgrade
Upgrade
redhat/389-ds-base-debugsourceto a version that resolves this vulnerability.Fixed in 2.4.5-25.module+el9d - Upgrade
Upgrade
redhat/389-ds-base-develto a version that resolves this vulnerability.Fixed in 2.4.5-25.module+el9d - Upgrade
Upgrade
redhat/389-ds-base-libsto a version that resolves this vulnerability.Fixed in 2.4.5-25.module+el9d - Upgrade
Upgrade
redhat/389-ds-base-libs-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.5-25.module+el9d - Upgrade
Upgrade
redhat/389-ds-base-snmpto a version that resolves this vulnerability.Fixed in 2.4.5-25.module+el9d - Upgrade
Upgrade
redhat/389-ds-base-snmp-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.5-25.module+el9d - Upgrade
Upgrade
redhat/cockpitto a version that resolves this vulnerability.Fixed in 389-ds-2.4.5-25.module+el9d - Upgrade
Upgrade
redhat/python3-lib389to a version that resolves this vulnerability.Fixed in 2.4.5-25.module+el9d - Upgrade
Upgrade
389-ds-baseto a version that resolves this vulnerability.Patch redhat-ds:12
Event History
Frequently Asked Questions
Which installed components should be considered affected?
Systems running the affected Red Hat 389 Directory Server package set are in scope, including the main 389-ds-base package and related libraries, development, SNMP, debug, and debuginfo packages listed in the advisory.
Can these issues be reached before LDAP authentication?
Two of the listed flaws are pre-authentication issues: LDAP filter injection in the CleanAllRUV status check and a stack buffer overflow triggered through unbounded replica ID parsing. The advisory also lists a NULL pointer dereference in the deref control plugin BER parser.
How can I determine whether my deployment needs the update?
Review whether 389-ds-base and its related packages are installed, then consult the referenced Red Hat bug reports and CVE records for affected-version and remediation details. This advisory does not provide package version numbers or temporary mitigations.