- Issued:
- 2026-08-17
- Updated:
- 2026-08-17
RHSA-2026:55532 - Security Advisory
Synopsis
Important: redhat-ds:11 security update
Type/Severity
Security Advisory: Important
Red Hat Lightspeed patch analysis
Identify and remediate systems affected by this advisory.
Topic
An update for the redhat-ds:11 module is now available for Red Hat Directory Server 11.9 for RHEL 8.
Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
Description
Red Hat Directory Server is an LDAPv3-compliant directory server. The suite of packages includes the Lightweight Directory Access Protocol (LDAP) server, as well as command-line utilities and Web UI packages for server administration.
Additional Changes:
For detailed information on changes in this release, see the Red Hat Directory Server 11.9 for RHEL 8 Release Notes linked from the References section.
Solution
For details on how to apply this update, which includes the changes described in this advisory, refer to:
Affected Products
- Red Hat Directory Server 11.9 x86_64
Fixes
- BZ - 2484802 - CVE-2026-11770 389-ds-base: 389-ds-base: pre-auth LDAP filter injection in CleanAllRUV status check
- BZ - 2485423 - CVE-2026-11788 389-ds-base: 389-ds-base: NULL pointer dereference in deref control plugin BER parser
- BZ - 2499961 - CVE-2026-15722 389-ds-base: 389-ds-base: pre-authentication stack buffer overflow in get_ruvelement_from_berval() via unbounded replica ID parsing
Red Hat Directory Server 11.9
| SRPM | |
|---|---|
| 389-ds-base-1.4.3.39-26.module+el8dsrv+24624+a4839c0f.src.rpm | SHA-256: c02a137c8d419db468e1e38e1b7eccf564fb44ed6b13a865f65f5f602784469c |
| x86_64 | |
| 389-ds-base-1.4.3.39-26.module+el8dsrv+24624+a4839c0f.x86_64.rpm | SHA-256: ceae9df91393610c8365e8b45db6992783b80b0a9c1bb2dbd3f6cc9084038f17 |
| 389-ds-base-debuginfo-1.4.3.39-26.module+el8dsrv+24624+a4839c0f.x86_64.rpm | SHA-256: 13271d25b7f8cbbd933ed64e9c422525dc1fc4c066e44f47fd8ef2852fcfaa75 |
| 389-ds-base-debugsource-1.4.3.39-26.module+el8dsrv+24624+a4839c0f.x86_64.rpm | SHA-256: 46de3d25f8d1bada0ddc71318ee7deefbc4b964032469c734ffb848fcc426d30 |
| 389-ds-base-devel-1.4.3.39-26.module+el8dsrv+24624+a4839c0f.x86_64.rpm | SHA-256: c4ac35479b70bb9b0faf2728db9d390a1553038aea381d4d4d9528363db7ed65 |
| 389-ds-base-legacy-tools-1.4.3.39-26.module+el8dsrv+24624+a4839c0f.x86_64.rpm | SHA-256: 17e17b455c2dd09c7c3f360000b4091e2b7a7c0c4f064bbaaf9df0ddda098000 |
| 389-ds-base-legacy-tools-debuginfo-1.4.3.39-26.module+el8dsrv+24624+a4839c0f.x86_64.rpm | SHA-256: d484ed8358a9629982612873c2522ee072554d25e2d5198a6c6a34ee25184621 |
| 389-ds-base-libs-1.4.3.39-26.module+el8dsrv+24624+a4839c0f.x86_64.rpm | SHA-256: a22b0634d55e824446398fdf7af8c5daf5118b354c307e6bb04cd3644ed966da |
| 389-ds-base-libs-debuginfo-1.4.3.39-26.module+el8dsrv+24624+a4839c0f.x86_64.rpm | SHA-256: 432c17ebfc2d9b8957bee6e3af66476d854d2f52f0d0ad38a9ded2bfd80d906e |
| 389-ds-base-snmp-1.4.3.39-26.module+el8dsrv+24624+a4839c0f.x86_64.rpm | SHA-256: a2a55044399ed81738ce05f3e764dd1bcffb9002a320c0ae97c56fce2374aa87 |
| 389-ds-base-snmp-debuginfo-1.4.3.39-26.module+el8dsrv+24624+a4839c0f.x86_64.rpm | SHA-256: f6ea234f9791b90a35897f0e55e9620bc385e9fd09826e3ade26da777d60358f |
| cockpit-389-ds-1.4.3.39-26.module+el8dsrv+24624+a4839c0f.noarch.rpm | SHA-256: a45b5b4c55d5241f309dc9dbb8f51805eb285082ba5e4e76ecad7caa2d871f1b |
| python3-lib389-1.4.3.39-26.module+el8dsrv+24624+a4839c0f.noarch.rpm | SHA-256: 6e8e5e25a7aec6c77c8d2033acf007d8d08bc48bb88eff59190be1daf77927a9 |
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/
