[El-errata] ELBA-2025-17897 Oracle Linux 10 389-ds-base bug fix and enhancement update

Errata Announcements for Oracle Linux el-errata at oss.oracle.com
Tue Oct 14 14:50:57 UTC 2025


Oracle Linux Bug Fix Advisory ELBA-2025-17897

http://linux.oracle.com/errata/ELBA-2025-17897.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
389-ds-base-3.0.6-13.el10_0.x86_64.rpm
389-ds-base-bdb-3.0.6-13.el10_0.x86_64.rpm
389-ds-base-devel-3.0.6-13.el10_0.x86_64.rpm
389-ds-base-libs-3.0.6-13.el10_0.x86_64.rpm
389-ds-base-snmp-3.0.6-13.el10_0.x86_64.rpm
python3-lib389-3.0.6-13.el10_0.noarch.rpm

aarch64:
389-ds-base-3.0.6-13.el10_0.aarch64.rpm
389-ds-base-bdb-3.0.6-13.el10_0.aarch64.rpm
389-ds-base-devel-3.0.6-13.el10_0.aarch64.rpm
389-ds-base-libs-3.0.6-13.el10_0.aarch64.rpm
389-ds-base-snmp-3.0.6-13.el10_0.aarch64.rpm
python3-lib389-3.0.6-13.el10_0.noarch.rpm


SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/389-ds-base-3.0.6-13.el10_0.src.rpm



Description of changes:

[3.0.6-13]
- Bump version to 3.0.6-13
- Resolves: RHEL-111230 - Error showing local password policy on web UI
  [rhel-10.0.z]
- Resolves: RHEL-113982 - AddressSanitizer: memory leak in
  memberof_add_memberof_attr [rhel-10.0.z]
- Resolves: RHEL-117749 - The numSubordinates value is not matching the
  number of direct children. [rhel-10.0.z]
- Resolves: RHEL-117753 - Crash if repl keep alive entry can not be created
  [rhel-10.0.z]
- Resolves: RHEL-117756 - Exception thrown by dsconf instance repl get_ruv
  [rhel-10.0.z]
- Resolves: RHEL-117763 - Replication online reinitialization of a large
  database gets stalled. [rhel-10.0.z]
- Resolves: RHEL-117766 - Statistics about index lookup report a wrong
  duration [rhel-10.0.z]
- Resolves: RHEL-117772 - When the server restarts after a crash, the RFE
  assumes memberof should be recomputed. It triggers a memberof fixup task,
  dirsrv became unresponsive. [rhel-10.0.z]
- Resolves: RHEL-117784 - Ignore the memberOfDeferredUpdate setting when
  LMDB is used.  [rhel-10.0.z]

[3.0.6-9]
- Bump version to 3.0.6-9
- Resolves: RHEL-80498 - Can't rename users member of automember rule
  [rhel-10.0.z]
- Resolves: RHEL-92053 - Memory leak in
  roles_cache_create_object_from_entry [rhel-10.0.z]
- Resolves: RHEL-107006 - Failure to get Server monitoring data when NDN
  cache is disabled. [rhel-10.0.z]
- Resolves: RHEL-109020 - Allow Uniqueness plugin to search uniqueness
  attributes using custom matching rules [rhel-10.0.z]
- Resolves: RHEL-109886 - Wrong backend database name syntax causes "Red
  Hat Directory Server" => "Databases" menu blank in Cockpit [rhel-10.0.z]
- Resolves: RHEL-109890 - RootDN Access Control Plugin with wildcards for
  IP addresses fails with an error "Invalid IP address" [rhel-10.0.z]
- Resolves: RHEL-109893 - On RHDS 12.6 The user password policy for a user
  was created, but the pwdpolicysubentry attribute for this user
  incorrectly points to the People OU password policy instead of the
  specific user policy.  [rhel-10.0.z]
- Resolves: RHEL-109898 - AddressSanitizer: leak in do_search [rhel-10.0.z]
- Resolves: RHEL-109905 - ns-slapd crashed when we add nsslapd-referral
  [rhel-10.0.z]
- Resolves: RHEL-109947 - CWE-284 dirsrv log rotation creates files with
  world readable permission [rhel-10.0.z]
- Resolves: RHEL-109956 - CWE-532 Created user password hash available to
  see in audit log [rhel-10.0.z]
- Resolves: RHEL-109959 - CWE-778 Log doesn't show what user gets password
  changed by administrator [rhel-10.0.z]
- Resolves: RHEL-110405 - RHDS12: Web console doesn't show Server Version
  [rhel-10.0.z]

[3.0.6-8]
- Bump version to 3.0.6-8
- Resolves: RHEL-89737 - dsconf backend replication monitor fails if
  replica id starts with 0 [rhel-10.0.z]
- Resolves: RHEL-89747 - ns-slapd crash in
  dbmdb_import_prepare_worker_entry() [rhel-10.0.z]
- Resolves: RHEL-89754 - Nested group does not receive memberOf attribute
  [rhel-10.0.z]
- Resolves: RHEL-89763 - dsidm Error: float() argument must be a string or
  a number, not 'NoneType' [rhel-10.0.z]
- Resolves: RHEL-89770 - Crash in __strlen_sse2 when using the nsRole
  filter rewriter. [rhel-10.0.z]
- Resolves: RHEL-89775 - Improve the "result" field of ipa-healthcheck if
  replicas are busy [rhel-10.0.z]
- Resolves: RHEL-89783 - RHDS12.2 NSMMReplicationPlugin - release_replica
  Unable to parse the response [rhel-10.0.z]
- Resolves: RHEL-95762 - Improve  error message when bulk import connection
  is closed [rhel-10.0.z]

[3.0.6-7]
- Resolves: RHEL-95445 - ns-slapd[xxxx]: segfault at 10d7d0d0 ip
  00007ff734050cdb sp 00007ff6de9f1430 error 6 in
  libslapd.so.0.1.0[7ff733ec0000+1b3000] [rhel-10.0.z]

[3.0.6-6]
- Bump version to 3.0.6-6
- Reverts: RHEL-80702 Increased memory consumption caused by NDN cache
  [rhel-10.0.z]

[3.0.6-5]
- Restore missing sources file

[3.0.6-4]
- Bump version to 3.0.6-4
- Resolves: RHEL-86063 Backport lib389 fixes required for WebUI
  [rhel-10.0.z]
- Resolves: RHEL-80702 Increased memory consumption caused by NDN cache
  [rhel-10.0.z]

[3.0.6-3]
- Bump version to 3.0.6-4
- Resolves: RHEL-79498 - Failed to set sslversionmax to TLS1.3 in FIPS mode
  with dsconf $INSTANCE security set --tls-protocol-max TLS1.3 [rhel-10]

[3.0.6-2]
- Bump version to 3.0.6-3
- Resolves: RHEL-5141 - [RFE] For each request, a ldap client can assign an
  identifier to be added in the logs
- Resolves: RHEL-77948 - ns-slapd crashes with data directory ≥ 2 days old
  [rhel-10]
- Resolves: RHEL-78342 - During import of entries without nsUniqueId, a
  supplier generates duplicate nsUniqueId (LMDB only)

[3.0.6-1]
- Update to 3.0.6
- Resolves: RHEL-1681 - [RFE] Log buffering for all log types
- Resolves: RHEL-5141 - [RFE] For each request, a ldap client can assign an
  identifier to be added in the logs
- Resolves: RHEL-38917 - dscreate interactive install shows a traceback
  when mdb is selected
- Resolves: RHEL-42485 - [RFE] pbkdf2 hardcoded parameters should be turned
  into configuration options
- Resolves: RHEL-59513 - [RFE] Port logconv.pl to python
- Resolves: RHEL-61253 - Make online import more robust
- Resolves: RHEL-69819 - "Duplicated DN detected" errors when creating
  indexes or importing entries. [rhel-10.0]
- Resolves: RHEL-70122 - Crash in attrlist_find() when the Account Policy
  plugin is enabled.
- Resolves: RHEL-74149 - backup/restore broken
- Resolves: RHEL-74154 - If an entry RDN is identical to the suffix, then
  Entryrdn gets broken during a reindex
- Resolves: RHEL-74159 - Crash during bind when acct policy plugin does not
  have "alwaysrecordlogin" set
- Resolves: RHEL-74164 - On replica consumer, account policy plugin fails
  to manage the last login history
- Resolves: RHEL-76020 - IPA LDAP error code T3 when no exceeded time limit
  from a paged search result [rhel-10]
- Resolves: RHEL-76838 - Unlocked and locked users having same error output
- Resolves: RHEL-76841 - Healthcheck tool should warn admin about creating
  a substring index on membership attribute



More information about the El-errata mailing list