Source: 389-ds-base Version: 3.1.2+vendor1-2 Severity: grave Tags: security upstream Justification: user security hole X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerabilities were published for 389-ds-base. CVE-2026-11770[0]: | A flaw was found in 389 Directory Server. An unauthenticated remote | attacker can inject LDAP search filters into the CleanAllRUV | replication status-check extended operation. Because the handler | performs the search against cn=config with elevated replication | plugin privileges and returns a boolean match result, the attacker | can extract sensitive server configuration metadata, including | replication bind DNs and password storage scheme information. CVE-2026-15722[1]: | A stack buffer overflow flaw was found in 389 Directory Server | (389-ds-base). The get_ruvelement_from_berval() function in | repl5_ruv.c copies digit characters from a network-supplied RUV | berval into a fixed 16-byte stack buffer without bounds checking. A | remote unauthenticated attacker can crash the LDAP server by sending | a crafted StartNSDS50ReplicationRequest extended operation | containing a replica ID field with more than 16 digit characters. | The overflow occurs during payload decoding, before any | authorization check. Stack protectors limit impact to denial of | service. If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-11770 https://www.cve.org/CVERecord?id=CVE-2026-11770 [1] https://security-tracker.debian.org/tracker/CVE-2026-15722 https://www.cve.org/CVERecord?id=CVE-2026-15722 Regards, Salvatore

