[El-errata] ELSA-2026-64785-0 Critical: Oracle Linux 10 389-ds-base security, bug fix, and enhancement update

Errata Announcements for Oracle Linux el-errata at oss.oracle.com
Wed Sep 9 21:25:18 UTC 2026


Oracle Linux Security Advisory ELSA-2026-64785-0

http://linux.oracle.com/errata/ELSA-2026-64785-0.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
389-ds-base-3.2.0-10.el10_2.x86_64.rpm
389-ds-base-bdb-3.2.0-10.el10_2.x86_64.rpm
389-ds-base-devel-3.2.0-10.el10_2.x86_64.rpm
389-ds-base-libs-3.2.0-10.el10_2.x86_64.rpm
389-ds-base-snmp-3.2.0-10.el10_2.x86_64.rpm
python3-lib389-3.2.0-10.el10_2.noarch.rpm

aarch64:
389-ds-base-3.2.0-10.el10_2.aarch64.rpm
389-ds-base-bdb-3.2.0-10.el10_2.aarch64.rpm
389-ds-base-devel-3.2.0-10.el10_2.aarch64.rpm
389-ds-base-libs-3.2.0-10.el10_2.aarch64.rpm
389-ds-base-snmp-3.2.0-10.el10_2.aarch64.rpm
python3-lib389-3.2.0-10.el10_2.noarch.rpm


SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/389-ds-base-3.2.0-10.el10_2.src.rpm

Related CVEs:

CVE-2026-18355
CVE-2026-18453
CVE-2026-18922
CVE-2026-76560
CVE-2026-78701




Description of changes:

[3.2.0-10]
- Bump version to 3.2.0-10
- Resolves: RHEL-220500 - CVE-2026-18355 389-ds-base: heap buffer overflow
  via SASL wrapped-record length lower-bound underflow in
  sasl_io_start_packet() [rhel-10.2.z]
- Resolves: RHEL-222320 - CVE-2026-18453 389-ds-base: pre-authentication
  NULL pointer dereference via paged results and USE_ONE_BACKEND control in
  op_shared_search [rhel-10.2.z]
- Resolves: RHEL-232863 -  CVE-2026-18922 389-ds-base: SASL PLAIN
  authentication allows privilege escalation to Directory Manager via stale
  identity in Cyrus SASL auxiliary property [rhel-10.2.z]
- Resolves: RHEL-244470 - lib389: set nsDS5ReplicaBindDNGroup before
  ensure_agreement() [rhel-10.2.z]
- Resolves: RHEL-245372 - CVE-2026-76560 389-ds-base: anonymous LDAP client
  can defeat SELFDN ACI bind-rule checks via empty bind DN [rhel-10.2.z]
- Resolves: RHEL-247859 - CVE-2026-78701 389-ds-base: CVE-2026-11610
  incomplete fix may introduce a connection-stall DoS [rhel-10.2.z]
- Resolves: RHEL-248770 - CVE-2026-11770 fix breaks replication total init
  when nsDS5ReplicaBindDNGroup is set after agreement creation
  [rhel-10.2.z]




More information about the El-errata mailing list