#1142285 389-ds-base: CVE-2026-11610 CVE-2026-14940 CVE-2026-14969 CVE-2026-15041

Package:
src:389-ds-base
Source:
src:389-ds-base
Submitter:
Salvatore Bonaccorso
Date:
2026-09-09 13:07:08 UTC
Severity:
normal
Tags:
#1142285#5
Date:
2026-07-17 06:50:11 UTC
From:
To:
Hi,

The following vulnerabilities were published for 389-ds-base.

We will need some help from you to identify the proper upstream fixes
for this set of CVEs. Thanks already.

CVE-2026-11610[0]:
| A heap buffer overflow flaw was found in the SASL I/O layer of 389
| Directory Server (389-ds-base). After a successful SASL bind with
| integrity protection (SSF > 0), an authenticated attacker can send a
| specially crafted oversized LDAP UNBIND packet that is copied into a
| 512-byte heap receive buffer without a bounds check in
| sasl_io_recv() in sasl_io.c. This allows up to approximately 2
| megabytes of attacker-controlled data to overflow the buffer,
| causing a denial of service (server crash). In FreeIPA and Red Hat
| Identity Management deployments, any domain user with a valid
| Kerberos ticket, any enrolled host, or any service account can
| trigger this vulnerability over the network after authenticating via
| GSSAPI. The vulnerable code path has existed since approximately
| 2013 (389-ds-base 1.3.2) and was not addressed by the CVE-2025-14905
| fix, which patched a separate heap overflow in schema.c only.


CVE-2026-14940[1]:
| A heap-buffer-overflow flaw was found in 389 Directory Server
| (389-ds-base). When normalizing a Distinguished Name (DN) that
| contains a legacy-quoted value encoding a multivalued nested
| Relative Distinguished Name (RDN), the server can write past the end
| of a heap allocation while sorting RDN attribute-value pairs. An
| unauthenticated remote attacker can trigger this condition by
| sending an LDAP operation whose DN reaches the DN normalization
| routine, such as a search with a crafted base DN. This can corrupt
| heap memory and may cause denial of service.


CVE-2026-14969[2]:
| A flaw was found in 389-ds-base where the LDBM backend attribute
| encryption uses a hardcoded static initialization vector for AES-CBC
| and 3DES-CBC operations, allowing an attacker with privileged
| filesystem access to detect plaintext equality across encrypted
| entries by comparing ciphertext blocks.


CVE-2026-15041[3]:
| A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password
| verification function uses standard memcmp() for comparing password
| hashes instead of a constant-time comparison function. A remote
| attacker could potentially use timing measurements of LDAP bind
| attempts to infer partial hash information, though practical
| exploitation is extremely difficult due to PBKDF2 computational
| overhead.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-11610
https://www.cve.org/CVERecord?id=CVE-2026-11610
[1] https://security-tracker.debian.org/tracker/CVE-2026-14940
https://www.cve.org/CVERecord?id=CVE-2026-14940
[2] https://security-tracker.debian.org/tracker/CVE-2026-14969
https://www.cve.org/CVERecord?id=CVE-2026-14969
[3] https://security-tracker.debian.org/tracker/CVE-2026-15041
https://www.cve.org/CVERecord?id=CVE-2026-15041

Regards,
Salvatore

#1142285#10
Date:
2026-09-09 13:05:04 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
389-ds-base, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1142285@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Timo Aaltonen <tjaalton@debian.org> (supplier of updated 389-ds-base package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Wed, 09 Sep 2026 15:38:38 +0300
Source: 389-ds-base
Built-For-Profiles: derivative.ubuntu noudeb
Architecture: source
Version: 3.3.1-1
Distribution: unstable
Urgency: medium
Maintainer: Debian FreeIPA Team <pkg-freeipa-devel@alioth-lists.debian.net>
Changed-By: Timo Aaltonen <tjaalton@debian.org>
Closes: 1119174 1139809 1139810 1139811 1139812 1139813 1139814 1139815 1139817 1139818 1139819 1139820 1142285 1143455 1143603 1144474 1144475
Changes:
 389-ds-base (3.3.1-1) unstable; urgency=medium
 .
   * New upstream release.
     - CVE-2026-11774 (Closes: #1139809)
     - CVE-2026-11610, CVE-2026-14940, CVE-2026-14969, CVE-2026-15041
       (Closes: #1142285)
     - CVE-2026-11611 (Closes: #1139820)
     - CVE-2026-11770, CVE-2026-15722 (Closes: #1143455)
     - CVE-2026-11785 (Closes: #1139810)
     - CVE-2026-11786 (Closes: #1139811)
     - CVE-2026-11787 (Closes: #1139812)
     - CVE-2026-11788 (Closes: #1139813)
     - CVE-2026-11789 (Closes: #1139814)
     - CVE-2026-11790 (Closes: #1139815)
     - CVE-2026-11792 (Closes: #1139817)
     - CVE-2026-11793 (Closes: #1139818)
     - CVE-2026-11884 (Closes: #1139819)
     - CVE-2026-18355
     - CVE-2026-18453
     - CVE-2026-18651 (Closes: #1143603)
     - CVE-2026-18663 (Closes: #1144475)
     - CVE-2026-19404 (Closes: #1144474)
     - CVE-2026-69152
     - CVE-2026-76560
     - CVE-2026-78701
   * install: Updated.
   * rules: Remove upstream sysusers conf, we have our own.
   * control: Drop libdb-dev from build-depends. (Closes: #1119174)
Checksums-Sha1:
 f1c015f86baf44b41d0e2f59463359eea2596a2b 2855 389-ds-base_3.3.1-1.dsc
 165b39fdb314f2d5d184fc49e3fecae2ca728274 19237049 389-ds-base_3.3.1.orig.tar.bz2
 bdab055237c18a549aadb0fc214c1df1aa7e07ad 26332 389-ds-base_3.3.1-1.debian.tar.xz
 6d72789c4e9a976412b44e0cb706c0e7e8c04e3d 11200 389-ds-base_3.3.1-1_source.buildinfo
Checksums-Sha256:
 4a6bd5a60ac2c91d171e7ce9b17b953bc1ad1e428cc5df8c99660c7461ee279f 2855 389-ds-base_3.3.1-1.dsc
 0a410a3231683e064e6a8d4f087881994970da36b8a0f3657e576012f53c98c4 19237049 389-ds-base_3.3.1.orig.tar.bz2
 4a1c2b4560cdc63ef43b94b78488c024eaa4b46d14100d94fc9add92a040da94 26332 389-ds-base_3.3.1-1.debian.tar.xz
 f59ed10c50468341f78dc2c70c4feedff17187adade1f1a38fadd2e26738e0a7 11200 389-ds-base_3.3.1-1_source.buildinfo
Files:
 6953d307e134f36d75eb59606b24b1f2 2855 net optional 389-ds-base_3.3.1-1.dsc
 5f36e34ef8137394783f9312a7894cb2 19237049 net optional 389-ds-base_3.3.1.orig.tar.bz2
 bbc2ccd4132ed12246937e6739e2fecc 26332 net optional 389-ds-base_3.3.1-1.debian.tar.xz
 2ae93efb4510d8e135573aa20ff2d687 11200 net optional 389-ds-base_3.3.1-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEdS3ifE3rFwGbS2Yjy3AxZaiJhNwFAmqhU2UACgkQy3AxZaiJ
hNw9wQ//ZK4CNc2Gm7YoAP9kfEOMyyE8i3z3+W6rbfa1xQLkdYK3s3J32ZWIQgsP
9yXHTTIH+Vw6XttBWH+hNf78XGxiBGt0ptvvl0dJ2PuYs0K5YJI6iGAIcuQxbmLQ
HirwpqaY+/6akvcbs228HwPKZSj006qkZyhOit8C3oPv/N41GEgGCwUcjrWEdwCz
fcAwxVbI7/LeG/3tp3o+xRntbjT4reVmUb0k2pRglgG/5OCQ/B+gFOKq1OddP/Pw
OKeYMC8aPxKRLlapI7Z6IVuLfV+gfmU2OvILHo3nT3sYnltoBI8qh+e+T2QJUjc9
ha77HkWmSWUhpWo6zFoqv+OhcvzkTcf6tRXq6i9oQ5B2sDWsI0Wc3EtSuAhST/bL
F7++bps4siO7RJKG3OxoBAz8LgRaB4Oet89VkQSgHJzeXX0GhLH2HPlevUeTUQIF
6bEbrMIET/kGZB82RBFrWip/YGIONL1Ln5wCs9LeGtOaROcbOUws/syMBIqNuAgG
We2E38mYt9xQKlSIGYnipdJbKL0KdXXV26Nzbm9f/sMxf5lwy/y0TARjGQdWDHp8
TfLqcGi86MuXmrDDJYi4wde+f4aYBNl2MroW+9m4XvaivneEZVHMuzaVrkDi2pSm
p7MwVgQ7oxlepGckex/bQIoWw0GNFze6wdtT0+tw+K4QExkcIjM=
=p47B
-----END PGP SIGNATURE-----