[Git][security-tracker-team/security-tracker][master] Track fixes for 38-ds-base
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Wed Sep 9 15:48:54 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
684b497b by Salvatore Bonaccorso at 2026-09-09T16:47:58+02:00
Track fixes for 38-ds-base
Note, that CVE-2026-69152 is not explicitly tracked for 389-ds-base as
well, it is underlying in src:node-brace-expansion.
Link: https://github.com/389ds/389-ds-base/issues/7527
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -4339,7 +4339,7 @@ CVE-2026-76578 (A flaw was found in FreeIPA. The self-managed OTP token ACI does
NOTE: FreeIPA in Debian only builds the client packages, not the server
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2519522
CVE-2026-76560 (A flaw was found in 389 Directory Server. The SELFDN ACI bind-rule eva ...)
- - 389-ds-base <unfixed>
+ - 389-ds-base 3.3.1-1
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2519521
CVE-2026-6431 (The User Profile Builder \u2013 Beautiful User Registration Forms, Use ...)
NOT-FOR-US: WordPress plugin
@@ -4369,10 +4369,10 @@ CVE-2026-18922 (A flaw was found in 389 Directory Server. During SASL PLAIN auth
CVE-2026-18796 (Any application that uses external QSPI flash for encrypted XIP o ...)
NOT-FOR-US: Nordic Semiconductor ASA
CVE-2026-18453 (A flaw was found in 389 Directory Server. A missing NULL pointer check ...)
- - 389-ds-base <unfixed>
+ - 389-ds-base 3.3.1-1
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2509696
CVE-2026-18355 (A heap buffer overflow flaw was found in the SASL I/O layer of 389 Dir ...)
- - 389-ds-base <unfixed>
+ - 389-ds-base 3.3.1-1
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2509186
CVE-2026-16028 (Protocol::HTTP2 versions before 1.14 for Perl allow memory exhaustion ...)
- libprotocol-http2-perl <unfixed>
@@ -34982,7 +34982,7 @@ CVE-2026-18673 (When kuma-dp is configured with the Envoy admin API on a Unix do
CVE-2026-18669 (IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to a privilege escalation a ...)
NOT-FOR-US: IBM
CVE-2026-18663 (A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() fu ...)
- - 389-ds-base <unfixed> (bug #1144475)
+ - 389-ds-base 3.3.1-1 (bug #1144475)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2510631
CVE-2026-18652 (Velociraptor allows reading Stacked result sets from the GUI. Velocira ...)
NOT-FOR-US: Rapid7
@@ -38573,7 +38573,7 @@ CVE-2026-19433 (Authorization Bypass Through User-Controlled Key in the contact
CVE-2026-19429
REJECTED
CVE-2026-19404 (A flaw was found in 389 Directory Server. The CleanAllRUV and Abort Cl ...)
- - 389-ds-base <unfixed> (bug #1144474)
+ - 389-ds-base 3.3.1-1 (bug #1144474)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2513036
CVE-2026-19278 (A flaw was found in StackRox/RHACS Central's Auth Machine-to-Machine ( ...)
NOT-FOR-US: Red Hat Advanced Cluster Security
@@ -44975,7 +44975,7 @@ CVE-2026-21548 (In nr modem, there is a possible improper input validation. This
CVE-2026-18718 (Ghidra contains an arbitrary code execution vulnerability in the Swift ...)
- ghidra <itp> (bug #923851)
CVE-2026-18651 (A flaw was found in 389 Directory Server. During SASL PLAIN authentica ...)
- - 389-ds-base <unfixed> (bug #1143603)
+ - 389-ds-base 3.3.1-1 (bug #1143603)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2510617
CVE-2026-18642 (Deserialization of untrusted data vulnerability in TUBITAK BILGEM Soft ...)
NOT-FOR-US: eta-otp-lock
@@ -46251,12 +46251,12 @@ CVE-2026-16503 (Deployment of the VPS.org one-click Supabase template deploys a
CVE-2026-16105 (A flaw was found in the RoleContainerResource component of Keycloak. T ...)
- keycloak <itp> (bug #1088287)
CVE-2026-15722 (A stack buffer overflow flaw was found in 389 Directory Server (389-ds ...)
- - 389-ds-base <unfixed> (bug #1143455)
+ - 389-ds-base 3.3.1-1 (bug #1143455)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2499961
CVE-2026-15227 (Missing authorization in Checkmk <2.5.0p10, <2.4.0p35, <2.3.0p49, and ...)
- ckeck-mk <removed>
CVE-2026-11770 (A flaw was found in 389 Directory Server. An unauthenticated remote at ...)
- - 389-ds-base <unfixed> (bug #1143455)
+ - 389-ds-base 3.3.1-1 (bug #1143455)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2484802
CVE-2026-10686 (Zephyr's IPv6 forwarding path re-sent routed unicast packets without e ...)
NOT-FOR-US: Zephyr, different from src:zephyr
@@ -69627,7 +69627,7 @@ CVE-2026-15043 (DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inv
NOTE: https://github.com/perl5-dbi/dbi/security/advisories/GHSA-mv45-ff6j-x9jp
NOTE: Fixed by: https://github.com/perl5-dbi/dbi/commit/e9742ef85a75867cbd696860e3bf3e32b681f98d (1.651)
CVE-2026-15041 (A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password v ...)
- - 389-ds-base <unfixed> (bug #1142285)
+ - 389-ds-base 3.3.1-1 (bug #1142285)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2498022
CVE-2026-15036 (A vulnerability was determined in Harness up to 2.28.2. This vulnerabi ...)
NOT-FOR-US: Harness
@@ -70037,10 +70037,10 @@ CVE-2026-23698 (Vtiger CRM through 8.4.0 contains an authenticated remote code e
CVE-2026-23697 (Vtiger CRM before 8.4.0 contains an authenticated file upload vulnerab ...)
NOT-FOR-US: Vtiger CRM
CVE-2026-14969 (A flaw was found in 389-ds-base where the LDBM backend attribute encry ...)
- - 389-ds-base <unfixed> (bug #1142285)
+ - 389-ds-base 3.3.1-1 (bug #1142285)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2497735
CVE-2026-14940 (A heap-buffer-overflow flaw was found in 389 Directory Server (389-ds- ...)
- - 389-ds-base <unfixed> (bug #1142285)
+ - 389-ds-base 3.3.1-1 (bug #1142285)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2497697
CVE-2026-14935 (A logic vulnerability was found in GStreamer's webrtcbin component. Th ...)
- gst-plugins-bad1.0 1.28.5-1
@@ -70111,7 +70111,7 @@ CVE-2026-12041 (The Chatra Live Chat + ChatBot + Cart Saver plugin for WordPress
CVE-2026-11798 (The Social Share, Social Login and Social Comments Plugin \u2013 Super ...)
NOT-FOR-US: WordPress plugin
CVE-2026-11610 (A heap buffer overflow flaw was found in the SASL I/O layer of 389 Dir ...)
- - 389-ds-base <unfixed> (bug #1142285)
+ - 389-ds-base 3.3.1-1 (bug #1142285)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2484414
NOTE: When fixing this issue the fix needs to be complete to not open up CVE-2026-78701
CVE-2026-11348 (Improper verification of cryptographic signature vulnerability in HAVE ...)
@@ -89202,7 +89202,7 @@ CVE-2026-11816 (Keras versions prior to 3.14.0 are vulnerable to a path traversa
- keras <removed>
[bullseye] - keras <end-of-life> (out of security support for bullseye)
CVE-2026-11774 (An integer overflow flaw was found in the SASL I/O layer of 389 Direct ...)
- - 389-ds-base <unfixed> (bug #1139809)
+ - 389-ds-base 3.3.1-1 (bug #1139809)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2484916
CVE-2026-11604 (An incorrect buffer size calculation in the epoch key generator in Ope ...)
NOT-FOR-US: OpenVPN ovpn-dco for Windows
@@ -89549,7 +89549,7 @@ CVE-2026-20252 (In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and
CVE-2026-20251 (In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13 ...)
NOT-FOR-US: Cisco
CVE-2026-11884 (A heap buffer overflow flaw was found in 389 Directory Server. When se ...)
- - 389-ds-base <unfixed> (bug #1139819)
+ - 389-ds-base 3.3.1-1 (bug #1139819)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2423624
CVE-2026-11859 (An HTML injection vulnerability in the "fetch links" email sent by Thi ...)
NOT-FOR-US: Canarytokens
@@ -90840,28 +90840,28 @@ CVE-2026-24064 (Waves Central for macOS versions 13.0.9 through 16.5.5 contain a
CVE-2026-22926 (Omnissa Workspace ONE\xae Assist for macOS contains a Local Privilege ...)
NOT-FOR-US: Omnissa
CVE-2026-11793 (A stack buffer overflow flaw was found in 389 Directory Server. The ch ...)
- - 389-ds-base <unfixed> (bug #1139818)
+ - 389-ds-base 3.3.1-1 (bug #1139818)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2484914
CVE-2026-11792 (A heap buffer overflow flaw was found in 389 Directory Server. When au ...)
- - 389-ds-base <unfixed> (bug #1139817)
+ - 389-ds-base 3.3.1-1 (bug #1139817)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2484915
CVE-2026-11790 (A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password s ...)
- - 389-ds-base <unfixed> (bug #1139815)
+ - 389-ds-base 3.3.1-1 (bug #1139815)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2485421
CVE-2026-11789 (A flaw was found in 389 Directory Server. The SMD5 password storage pl ...)
- - 389-ds-base <unfixed> (bug #1139814)
+ - 389-ds-base 3.3.1-1 (bug #1139814)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2485422
CVE-2026-11788 (A flaw was found in 389 Directory Server. The dereference control plug ...)
- - 389-ds-base <unfixed> (bug #1139813)
+ - 389-ds-base 3.3.1-1 (bug #1139813)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2485423
CVE-2026-11787 (A flaw was found in 389 Directory Server. The ldap_utf8prev() function ...)
- - 389-ds-base <unfixed> (bug #1139812)
+ - 389-ds-base 3.3.1-1 (bug #1139812)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2485425
CVE-2026-11786 (A flaw was found in 389 Directory Server. The LDIF parser reads past t ...)
- - 389-ds-base <unfixed> (bug #1139811)
+ - 389-ds-base 3.3.1-1 (bug #1139811)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2485426
CVE-2026-11785 (A flaw was found in 389 Directory Server. A type confusion in the SSO ...)
- - 389-ds-base <unfixed> (bug #1139810)
+ - 389-ds-base 3.3.1-1 (bug #1139810)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2485427
CVE-2026-11764 (When creating an export of all reusable media, the secrets of connecte ...)
NOT-FOR-US: rami.io products
@@ -92045,7 +92045,7 @@ CVE-2026-25555 (OpenBullet2 through version 0.3.2 contains an authentication byp
CVE-2026-22164 (Software installed and run as a non-privileged user may conduct improp ...)
NOT-FOR-US: Imagination Technologies
CVE-2026-11611 (A flaw was found in 389 Directory Server. The Content Synchronization ...)
- - 389-ds-base <unfixed> (bug #1139820)
+ - 389-ds-base 3.3.1-1 (bug #1139820)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2485424
CVE-2026-11577
REJECTED
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/684b497bafec39917506c0fbe8accc32e3d88525
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/684b497bafec39917506c0fbe8accc32e3d88525
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260909/864ad186/attachment.htm>
More information about the debian-security-tracker-commits
mailing list