SUSE SLES15 Security Update : 389-ds (SUSE-SU-2026:3138-1)

medium Nessus Plugin ID 328679

Language:

Synopsis

The remote SUSE host is missing one or more security updates.

Description

The remote SUSE Linux SLES15 / SLES_SAP15 host has packages installed that are affected by multiple vulnerabilities as referenced in the SUSE-SU-2026:3138-1 advisory.

This update for 389-ds fixes the following issues

- Update to version 2.7.0~git212.9b0755edb.
- CVE-2026-11610: heap buffer overflow in `sasl_io_recv()` via padded SASL UNBIND (bsc#1270695).
- CVE-2026-11611: content synchronization persistent search plugin can allow unbounded memory growth (bsc#1267975).
- CVE-2026-11774: integer overflow in SASL packet length bypasses size limit leading to heap buffer overflow (bsc#1268298).
- CVE-2026-11785: type confusion in the SSO token handler can cause partial stack address information disclosure (bsc#1268065).
- CVE-2026-11786: lack of length check can cause an out-of-bounds read (bsc#1268064).
- CVE-2026-11787: lack of bounds check can lead to a heap buffer overread (bsc#1268062).
- CVE-2026-11788: lack of allocation failure check can lead to NULL pointer dereference (bsc#1268057).
- CVE-2026-11789: crafted SMD5 hash can lead to an integer underflow (bsc#1268058).
- CVE-2026-11790: crafted password hash can cause excessive CPU consumption (bsc#1268060).
- CVE-2026-11791: schema reload triggered during concurrent LDAP query traffic can lead to a use-after- free (bsc#1268047).
- CVE-2026-11792: password value shorter than 23 characters can cause a heap buffer overflow (bsc#1268046).
- CVE-2026-11793: crafted `nsDS5ReplicaCredentials` can lead to a stack buffer overflow (bsc#1268041).
- CVE-2026-11884: remote code execution and denial of service via heap buffer overflow (bsc#1268115).
- CVE-2026-12528: heap buffer overflows in `__aclp__normalize_acltxt()` (bsc#1268491).

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected 389-ds, 389-ds-devel, lib389 and / or libsvrcore0 packages.

See Also

https://bugzilla.suse.com/1267975

https://bugzilla.suse.com/1268041

https://bugzilla.suse.com/1268046

https://bugzilla.suse.com/1268047

https://bugzilla.suse.com/1268057

https://bugzilla.suse.com/1268058

https://bugzilla.suse.com/1268060

https://bugzilla.suse.com/1268062

https://bugzilla.suse.com/1268064

https://bugzilla.suse.com/1268065

https://bugzilla.suse.com/1268115

https://bugzilla.suse.com/1268298

https://bugzilla.suse.com/1268491

https://bugzilla.suse.com/1269120

https://bugzilla.suse.com/1270695

https://www.suse.com/security/cve/CVE-2026-11610

https://www.suse.com/security/cve/CVE-2026-11611

https://www.suse.com/security/cve/CVE-2026-11774

https://www.suse.com/security/cve/CVE-2026-11785

https://www.suse.com/security/cve/CVE-2026-11786

https://www.suse.com/security/cve/CVE-2026-11787

https://www.suse.com/security/cve/CVE-2026-11788

https://www.suse.com/security/cve/CVE-2026-11789

https://www.suse.com/security/cve/CVE-2026-11790

https://www.suse.com/security/cve/CVE-2026-11791

https://www.suse.com/security/cve/CVE-2026-11792

https://www.suse.com/security/cve/CVE-2026-11793

https://www.suse.com/security/cve/CVE-2026-11884

https://www.suse.com/security/cve/CVE-2026-12528

http://www.nessus.org/u?2a9c1b18

Plugin Details

Severity: Medium

ID: 328679

File Name: suse_SU-2026-3138-1.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 7/21/2026

Updated: 7/21/2026

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.9

Percentile: 96.92

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:N/A:N

CVSS Score Source: CVE-2026-11786

CVSS v3

Risk Factor: Medium

Base Score: 6.5

Temporal Score: 5.7

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:novell:suse_linux:15, p-cpe:/a:novell:suse_linux:389-ds-devel, p-cpe:/a:novell:suse_linux:389-ds, p-cpe:/a:novell:suse_linux:lib389, p-cpe:/a:novell:suse_linux:libsvrcore0

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 7/20/2026

Vulnerability Publication Date: 6/8/2026

Reference Information

CVE: CVE-2026-11610, CVE-2026-11611, CVE-2026-11774, CVE-2026-11785, CVE-2026-11786, CVE-2026-11787, CVE-2026-11788, CVE-2026-11789, CVE-2026-11790, CVE-2026-11791, CVE-2026-11792, CVE-2026-11793, CVE-2026-11884, CVE-2026-12528

SuSE: SUSE-SU-2026:3138-1