[El-errata] ELSA-2026-36196 Important: Oracle Linux 10 389-ds-base security update

Errata Announcements for Oracle Linux el-errata at oss.oracle.com
Wed Jul 22 11:26:21 UTC 2026


Oracle Linux Security Advisory ELSA-2026-36196

http://linux.oracle.com/errata/ELSA-2026-36196.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
389-ds-base-3.2.0-8.el10_2.x86_64.rpm
389-ds-base-bdb-3.2.0-8.el10_2.x86_64.rpm
389-ds-base-devel-3.2.0-8.el10_2.x86_64.rpm
389-ds-base-libs-3.2.0-8.el10_2.x86_64.rpm
389-ds-base-snmp-3.2.0-8.el10_2.x86_64.rpm
python3-lib389-3.2.0-8.el10_2.noarch.rpm

aarch64:
389-ds-base-3.2.0-8.el10_2.aarch64.rpm
389-ds-base-bdb-3.2.0-8.el10_2.aarch64.rpm
389-ds-base-devel-3.2.0-8.el10_2.aarch64.rpm
389-ds-base-libs-3.2.0-8.el10_2.aarch64.rpm
389-ds-base-snmp-3.2.0-8.el10_2.aarch64.rpm
python3-lib389-3.2.0-8.el10_2.noarch.rpm


SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/389-ds-base-3.2.0-8.el10_2.src.rpm

Related CVEs:

CVE-2026-11610
CVE-2026-11774




Description of changes:

[3.2.0-8]
- Bump version to 3.2.0-8
- Resolves: RHEL-182152 - CVE-2026-11610 389-ds-base: 389-ds-base: Heap
  buffer overflow in sasl_io_recv() via padded SASL UNBIND [rhel-10.2.z]
- Resolves: RHEL-183105 - CVE-2026-11774 389-ds-base: 389-ds-base: integer
  overflow in SASL packet length bypasses size limit leading to heap buffer
  overflow [rhel-10.2.z]

[3.2.0-7]
- Bump version to 3.2.0-7
- Resolves: RHEL-170271 - DS 12 does not handle escape char in bind user
  [rhel-10.2.z]
- Resolves: RHEL-170276 - dnaSharedConfig: "dnaPortNum: 0" [rhel-10.2.z]
- Resolves: RHEL-170281 - Memory leaks in syncrepl plugin during persistent
  search operations [rhel-10.2.z]
- Resolves: RHEL-170363 - access log - suspicious wtime  optime negative
  and large values in internal op [rhel-10.2.z]
- Resolves: RHEL-170478 - An online reinitialization with LMDB is
  terminating the receiving server [rhel-10.2.z]
- Resolves: RHEL-170481 - dsctl healthcheck DSMOLE0001 inaccurate
  recommendations when there is more than 1 LDAP backend [rhel-10.2.z]
- Resolves: RHEL-170515 - Possible memory leak when using the Retro
  Changelog plugin. [rhel-10.2.z]
- Resolves: RHEL-174526 - [RFE] Add OS-level thread names to all server
  threads [rhel-10.2.z]
- Resolves: RHEL-178074 - CVE-2026-9064 389-ds-base: 389-ds-base: unbounded
  LDAP controls count in get_ldapmessage_controls_ext() causes CPU and heap
  amplification (remote DoS) [rhel-10.2]
- Resolves: RHEL-180718 - Online export is failing when using the option
  "-s" [rhel-10.2.z]
- Resolves: RHEL-183897 - Server shutdown during online reindex may lead to
  data loss [rhel-10.2.z]
- Resolves: RHEL-183898 - Error: NssSsl.add_cert() got an unexpected
  keyword argument 'input_file' [rhel-10.2.z]
- Resolves: RHEL-183899 - Replication errors in logs [rhel-10.2.z]
- Resolves: RHEL-183900 - Substring index produces empty results and can
  crash when non-default nsSubStrBegin/nsSubStrEnd lengths are configured
  [rhel-10.2.z]




More information about the El-errata mailing list