#1139809 389-ds-base: CVE-2026-11774

Package:
src:389-ds-base
Source:
src:389-ds-base
Submitter:
Moritz Mühlenhoff
Date:
2026-09-09 13:07:02 UTC
Severity:
normal
Tags:
#1139809#5
Date:
2026-06-12 14:17:32 UTC
From:
To:
Hi,

The following vulnerability was published for 389-ds-base.

CVE-2026-11774[0]:
| An integer overflow flaw was found in the SASL I/O layer of 389
| Directory Server (389-ds-base). In sasl_io_start_packet(), adding
| sizeof(uint32_t) to a crafted SASL packet length prefix of
| 0xFFFFFFFC causes unsigned wraparound to zero, bypassing the
| nsslapd-maxsasliosize limit and leading to a heap buffer overflow of
| up to approximately 2 megabytes of attacker-controlled data. After a
| successful SASL bind with integrity protection (SSF > 0), a remote
| attacker can cause a Denial of Service (DoS) or achieve Remote Code
| Execution (RCE). In FreeIPA and Red Hat Identity Management
| deployments, any domain user with a valid Kerberos ticket, enrolled
| host, or service account can trigger this vulnerability over the
| network. This flaw is independent of CVE-2025-14905, which patched
| schema.c only and did not modify sasl_io.c.

https://bugzilla.redhat.com/show_bug.cgi?id=2484916


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-11774
https://www.cve.org/CVERecord?id=CVE-2026-11774

Please adjust the affected versions in the BTS as needed.

#1139809#12
Date:
2026-09-09 13:05:04 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
389-ds-base, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1139809@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Timo Aaltonen <tjaalton@debian.org> (supplier of updated 389-ds-base package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Wed, 09 Sep 2026 15:38:38 +0300
Source: 389-ds-base
Built-For-Profiles: derivative.ubuntu noudeb
Architecture: source
Version: 3.3.1-1
Distribution: unstable
Urgency: medium
Maintainer: Debian FreeIPA Team <pkg-freeipa-devel@alioth-lists.debian.net>
Changed-By: Timo Aaltonen <tjaalton@debian.org>
Closes: 1119174 1139809 1139810 1139811 1139812 1139813 1139814 1139815 1139817 1139818 1139819 1139820 1142285 1143455 1143603 1144474 1144475
Changes:
 389-ds-base (3.3.1-1) unstable; urgency=medium
 .
   * New upstream release.
     - CVE-2026-11774 (Closes: #1139809)
     - CVE-2026-11610, CVE-2026-14940, CVE-2026-14969, CVE-2026-15041
       (Closes: #1142285)
     - CVE-2026-11611 (Closes: #1139820)
     - CVE-2026-11770, CVE-2026-15722 (Closes: #1143455)
     - CVE-2026-11785 (Closes: #1139810)
     - CVE-2026-11786 (Closes: #1139811)
     - CVE-2026-11787 (Closes: #1139812)
     - CVE-2026-11788 (Closes: #1139813)
     - CVE-2026-11789 (Closes: #1139814)
     - CVE-2026-11790 (Closes: #1139815)
     - CVE-2026-11792 (Closes: #1139817)
     - CVE-2026-11793 (Closes: #1139818)
     - CVE-2026-11884 (Closes: #1139819)
     - CVE-2026-18355
     - CVE-2026-18453
     - CVE-2026-18651 (Closes: #1143603)
     - CVE-2026-18663 (Closes: #1144475)
     - CVE-2026-19404 (Closes: #1144474)
     - CVE-2026-69152
     - CVE-2026-76560
     - CVE-2026-78701
   * install: Updated.
   * rules: Remove upstream sysusers conf, we have our own.
   * control: Drop libdb-dev from build-depends. (Closes: #1119174)
Checksums-Sha1:
 f1c015f86baf44b41d0e2f59463359eea2596a2b 2855 389-ds-base_3.3.1-1.dsc
 165b39fdb314f2d5d184fc49e3fecae2ca728274 19237049 389-ds-base_3.3.1.orig.tar.bz2
 bdab055237c18a549aadb0fc214c1df1aa7e07ad 26332 389-ds-base_3.3.1-1.debian.tar.xz
 6d72789c4e9a976412b44e0cb706c0e7e8c04e3d 11200 389-ds-base_3.3.1-1_source.buildinfo
Checksums-Sha256:
 4a6bd5a60ac2c91d171e7ce9b17b953bc1ad1e428cc5df8c99660c7461ee279f 2855 389-ds-base_3.3.1-1.dsc
 0a410a3231683e064e6a8d4f087881994970da36b8a0f3657e576012f53c98c4 19237049 389-ds-base_3.3.1.orig.tar.bz2
 4a1c2b4560cdc63ef43b94b78488c024eaa4b46d14100d94fc9add92a040da94 26332 389-ds-base_3.3.1-1.debian.tar.xz
 f59ed10c50468341f78dc2c70c4feedff17187adade1f1a38fadd2e26738e0a7 11200 389-ds-base_3.3.1-1_source.buildinfo
Files:
 6953d307e134f36d75eb59606b24b1f2 2855 net optional 389-ds-base_3.3.1-1.dsc
 5f36e34ef8137394783f9312a7894cb2 19237049 net optional 389-ds-base_3.3.1.orig.tar.bz2
 bbc2ccd4132ed12246937e6739e2fecc 26332 net optional 389-ds-base_3.3.1-1.debian.tar.xz
 2ae93efb4510d8e135573aa20ff2d687 11200 net optional 389-ds-base_3.3.1-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEdS3ifE3rFwGbS2Yjy3AxZaiJhNwFAmqhU2UACgkQy3AxZaiJ
hNw9wQ//ZK4CNc2Gm7YoAP9kfEOMyyE8i3z3+W6rbfa1xQLkdYK3s3J32ZWIQgsP
9yXHTTIH+Vw6XttBWH+hNf78XGxiBGt0ptvvl0dJ2PuYs0K5YJI6iGAIcuQxbmLQ
HirwpqaY+/6akvcbs228HwPKZSj006qkZyhOit8C3oPv/N41GEgGCwUcjrWEdwCz
fcAwxVbI7/LeG/3tp3o+xRntbjT4reVmUb0k2pRglgG/5OCQ/B+gFOKq1OddP/Pw
OKeYMC8aPxKRLlapI7Z6IVuLfV+gfmU2OvILHo3nT3sYnltoBI8qh+e+T2QJUjc9
ha77HkWmSWUhpWo6zFoqv+OhcvzkTcf6tRXq6i9oQ5B2sDWsI0Wc3EtSuAhST/bL
F7++bps4siO7RJKG3OxoBAz8LgRaB4Oet89VkQSgHJzeXX0GhLH2HPlevUeTUQIF
6bEbrMIET/kGZB82RBFrWip/YGIONL1Ln5wCs9LeGtOaROcbOUws/syMBIqNuAgG
We2E38mYt9xQKlSIGYnipdJbKL0KdXXV26Nzbm9f/sMxf5lwy/y0TARjGQdWDHp8
TfLqcGi86MuXmrDDJYi4wde+f4aYBNl2MroW+9m4XvaivneEZVHMuzaVrkDi2pSm
p7MwVgQ7oxlepGckex/bQIoWw0GNFze6wdtT0+tw+K4QExkcIjM=
=p47B
-----END PGP SIGNATURE-----