Synopsis
The remote SUSE host is missing one or more security updates.
Description
The remote SUSE Linux SLES15 / SLES_SAP15 host has packages installed that are affected by multiple vulnerabilities as referenced in the SUSE-SU-2026:3137-1 advisory.
Update to version 2.2.10~git255.752643c78.
Security issues fixed:
- CVE-2026-11610: missing bounds check in `sasl_io_recv()` can lead to a heap buffer overflow when processing a specially crafted oversized LDAP UNBIND packet (bsc#1270695).
- CVE-2026-11611: Content Synchronization persistent search plugin allows unbounded memory growth when an authenticated client stops reading sync responses(bsc#1267975).
- CVE-2026-11774: integer overflow in `sasl_io_start_packet()` can lead to heap buffer overflow when processing a crafted SASL packet length prefix (bsc#1268298).
- CVE-2026-11785: type confusion in the SSO token handler can cause partial stack address information disclosure in LDA responses (bsc#1268065).
- CVE-2026-11786: out-of-bounds read in the LDIF parser when processing attribute types with trailing semicolons during database import (bsc#1268064).
- CVE-2026-11787: missing bounds check in the `ldap_utf8prev()` functioncan can lead to a heap buffer overread in string filter parsing(bsc#1268062).
- CVE-2026-11788: missing allocation check in the dereference control plugin before using a BER structure can lead to LDAP server crash when the system is under memory pressure (bsc#1268057).
- CVE-2026-11789: integer underflow in the SMD5 password storage plugin can lead to a buffer overread when computing salt length from a crafted password hash shorter than 16 bytes (bsc#1268058).
- CVE-2026-11790: improper bounds enforcement in the BKDF2-SHA256 password storage plugin can lead to excessive resource consumption during authentication and cause a DoS (bsc#1268060).
- CVE-2026-11791: use-after-free in the schema reload mechanism can lead to a `ns-slapd` crash when concurrent LDAP query traffic is active (bsc#1268047).
- CVE-2026-11792: missing checks in `create_masked_entry_string` can lead to a heap and log output corruption whe a short cleartext password is logged (bsc#1268046).
- CVE-2026-11793: missing bounds check in `checkPrefix()` can lead to a stack buffer overflow when processing an algorithm ID during parsing of reversible-encrypted attribute values (bsc#1268041).
- CVE-2026-11884: improper string management can lead to heap buffer overflow when serializing objectclass definitions (bsc#1268115).
- CVE-2026-12528: missing length checks in the `__aclp__normalize_acltxt()` function can lead to heap buffer overflow when processing a malformed ACI string (bsc#1268491).
Other updates and bugfixes:
- Version 2.2.10~git255.752643c78.
* Issue 7406 - Fix `ldap-agent` SNMP stats file loading (#7630)
* Issue 7621 - Stack Buffer Overflow in Password `checkPrefix`
* Issue 7623 - Heap Buffer Overflow in `389-ds-base` Audit Log Password Masking
* Issue 6625 - Backport `get_pid` to fix `check_asan_report` (#7625)
* Issue 7602 - CI - `lib389` user compare fails due to parentid mismatch (#7603)
* Issue 7537 - CI - Fix replication log monitoring parser/timing failures (#7592)
* Issue 7593 - Fix testimony docstring for SASL overflow test (#7606)
* Issue 7530 - CI - Stabilize DNA plugin replication tests timing out in CI (#7572)
* Issue 7593 - Reject invalid SASL packet length values in `sasl_io_start_packet` (#7594)
* Issue 3555 - UI - Fix audit issue with `npm` - `ws`, `js-yaml`, `js-yaml` , `postcss`, `uuid`
* Issue 7541 - Add invalid ACL text header regression test (#7591)
* Issue 7541 - heap-buffer-overflows in `__aclp__normalize_acltxt()` (#7542)
* Issue 7576 - Fix leak of temporary attribute syntax hash tables after schema reload
* Issue 7558 - During online import, the IDL should be created with in-depth first approach (#7559)
* Issue 7500 - Prevent unsigned integer underflow during stalled import
* Issue 7560 - `lib389` - Add helper function for checking ASAN files
* Issue 7539 - Server shutdown during online reindex may lead to data loss (#7540)
* Issue 7549 - Substring index should validate minimum `nsSubStrBegin`/`nsSubStrEnd` values (#7550)
* Issue 7440 - Substring index produces empty results and can crash when non-default `nsSubStrBegin`/`nsSubStrEnd` lengths are configured (#7441)
* Fix test389 imports on older branches
* Issue 7437 - `LeakSanitizer`: memory leaks in CoS cache error paths (#7438)
* Issue 6922 - `AddressSanitizer`: leaks found by acl test suite
* Issue 3555 - UI - Fix audit issue with `npm` - `brace-expansion` (#7556)
* Issue 7554 - deref plugin null pointer dereference if `ber_init` fails
* Issue 7514 - Crash when doing moddn on very large subtree
* Issue 7516 - `dblayer_bulk_nextdata` should not return an error when maxrecords is hit
Tenable has extracted the preceding description block directly from the SUSE security advisory.
Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
Solution
Update the affected 389-ds, 389-ds-devel, lib389 and / or libsvrcore0 packages.
Plugin Details
File Name: suse_SU-2026-3137-1.nasl
Agent: unix
Supported Sensors: Nessus Agent, Continuous Assessment, Nessus
Risk Information
Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:N/A:N
Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C
Vulnerability Information
CPE: cpe:/o:novell:suse_linux:15, p-cpe:/a:novell:suse_linux:389-ds-devel, p-cpe:/a:novell:suse_linux:389-ds, p-cpe:/a:novell:suse_linux:lib389, p-cpe:/a:novell:suse_linux:libsvrcore0
Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list
Exploit Ease: No known exploits are available
Patch Publication Date: 7/20/2026
Vulnerability Publication Date: 6/8/2026
Reference Information
CVE: CVE-2026-11610, CVE-2026-11611, CVE-2026-11774, CVE-2026-11785, CVE-2026-11786, CVE-2026-11787, CVE-2026-11788, CVE-2026-11789, CVE-2026-11790, CVE-2026-11791, CVE-2026-11792, CVE-2026-11793, CVE-2026-11884, CVE-2026-12528
SuSE: SUSE-SU-2026:3137-1