SUSE SLES15 Security Update : 389-ds (SUSE-SU-2026:3137-1)

medium Nessus Plugin ID 328689

Synopsis

The remote SUSE host is missing one or more security updates.

Description

The remote SUSE Linux SLES15 / SLES_SAP15 host has packages installed that are affected by multiple vulnerabilities as referenced in the SUSE-SU-2026:3137-1 advisory.

Update to version 2.2.10~git255.752643c78.

Security issues fixed:

- CVE-2026-11610: missing bounds check in `sasl_io_recv()` can lead to a heap buffer overflow when processing a specially crafted oversized LDAP UNBIND packet (bsc#1270695).
- CVE-2026-11611: Content Synchronization persistent search plugin allows unbounded memory growth when an authenticated client stops reading sync responses(bsc#1267975).
- CVE-2026-11774: integer overflow in `sasl_io_start_packet()` can lead to heap buffer overflow when processing a crafted SASL packet length prefix (bsc#1268298).
- CVE-2026-11785: type confusion in the SSO token handler can cause partial stack address information disclosure in LDA responses (bsc#1268065).
- CVE-2026-11786: out-of-bounds read in the LDIF parser when processing attribute types with trailing semicolons during database import (bsc#1268064).
- CVE-2026-11787: missing bounds check in the `ldap_utf8prev()` functioncan can lead to a heap buffer overread in string filter parsing(bsc#1268062).
- CVE-2026-11788: missing allocation check in the dereference control plugin before using a BER structure can lead to LDAP server crash when the system is under memory pressure (bsc#1268057).
- CVE-2026-11789: integer underflow in the SMD5 password storage plugin can lead to a buffer overread when computing salt length from a crafted password hash shorter than 16 bytes (bsc#1268058).
- CVE-2026-11790: improper bounds enforcement in the BKDF2-SHA256 password storage plugin can lead to excessive resource consumption during authentication and cause a DoS (bsc#1268060).
- CVE-2026-11791: use-after-free in the schema reload mechanism can lead to a `ns-slapd` crash when concurrent LDAP query traffic is active (bsc#1268047).
- CVE-2026-11792: missing checks in `create_masked_entry_string` can lead to a heap and log output corruption whe a short cleartext password is logged (bsc#1268046).
- CVE-2026-11793: missing bounds check in `checkPrefix()` can lead to a stack buffer overflow when processing an algorithm ID during parsing of reversible-encrypted attribute values (bsc#1268041).
- CVE-2026-11884: improper string management can lead to heap buffer overflow when serializing objectclass definitions (bsc#1268115).
- CVE-2026-12528: missing length checks in the `__aclp__normalize_acltxt()` function can lead to heap buffer overflow when processing a malformed ACI string (bsc#1268491).

Other updates and bugfixes:

- Version 2.2.10~git255.752643c78.
* Issue 7406 - Fix `ldap-agent` SNMP stats file loading (#7630)
* Issue 7621 - Stack Buffer Overflow in Password `checkPrefix`
* Issue 7623 - Heap Buffer Overflow in `389-ds-base` Audit Log Password Masking
* Issue 6625 - Backport `get_pid` to fix `check_asan_report` (#7625)
* Issue 7602 - CI - `lib389` user compare fails due to parentid mismatch (#7603)
* Issue 7537 - CI - Fix replication log monitoring parser/timing failures (#7592)
* Issue 7593 - Fix testimony docstring for SASL overflow test (#7606)
* Issue 7530 - CI - Stabilize DNA plugin replication tests timing out in CI (#7572)
* Issue 7593 - Reject invalid SASL packet length values in `sasl_io_start_packet` (#7594)
* Issue 3555 - UI - Fix audit issue with `npm` - `ws`, `js-yaml`, `js-yaml` , `postcss`, `uuid`
* Issue 7541 - Add invalid ACL text header regression test (#7591)
* Issue 7541 - heap-buffer-overflows in `__aclp__normalize_acltxt()` (#7542)
* Issue 7576 - Fix leak of temporary attribute syntax hash tables after schema reload
* Issue 7558 - During online import, the IDL should be created with in-depth first approach (#7559)
* Issue 7500 - Prevent unsigned integer underflow during stalled import
* Issue 7560 - `lib389` - Add helper function for checking ASAN files
* Issue 7539 - Server shutdown during online reindex may lead to data loss (#7540)
* Issue 7549 - Substring index should validate minimum `nsSubStrBegin`/`nsSubStrEnd` values (#7550)
* Issue 7440 - Substring index produces empty results and can crash when non-default `nsSubStrBegin`/`nsSubStrEnd` lengths are configured (#7441)
* Fix test389 imports on older branches
* Issue 7437 - `LeakSanitizer`: memory leaks in CoS cache error paths (#7438)
* Issue 6922 - `AddressSanitizer`: leaks found by acl test suite
* Issue 3555 - UI - Fix audit issue with `npm` - `brace-expansion` (#7556)
* Issue 7554 - deref plugin null pointer dereference if `ber_init` fails
* Issue 7514 - Crash when doing moddn on very large subtree
* Issue 7516 - `dblayer_bulk_nextdata` should not return an error when maxrecords is hit

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected 389-ds, 389-ds-devel, lib389 and / or libsvrcore0 packages.

See Also

https://bugzilla.suse.com/1267975

https://bugzilla.suse.com/1268041

https://bugzilla.suse.com/1268046

https://bugzilla.suse.com/1268047

https://bugzilla.suse.com/1268057

https://bugzilla.suse.com/1268058

https://bugzilla.suse.com/1268060

https://bugzilla.suse.com/1268062

https://bugzilla.suse.com/1268064

https://bugzilla.suse.com/1268065

https://bugzilla.suse.com/1268115

https://bugzilla.suse.com/1268298

https://bugzilla.suse.com/1268491

https://bugzilla.suse.com/1269120

https://bugzilla.suse.com/1270695

https://www.suse.com/security/cve/CVE-2026-11610

https://www.suse.com/security/cve/CVE-2026-11611

https://www.suse.com/security/cve/CVE-2026-11774

https://www.suse.com/security/cve/CVE-2026-11785

https://www.suse.com/security/cve/CVE-2026-11786

https://www.suse.com/security/cve/CVE-2026-11787

https://www.suse.com/security/cve/CVE-2026-11788

https://www.suse.com/security/cve/CVE-2026-11789

https://www.suse.com/security/cve/CVE-2026-11790

https://www.suse.com/security/cve/CVE-2026-11791

https://www.suse.com/security/cve/CVE-2026-11792

https://www.suse.com/security/cve/CVE-2026-11793

https://www.suse.com/security/cve/CVE-2026-11884

https://www.suse.com/security/cve/CVE-2026-12528

http://www.nessus.org/u?3303a511

Plugin Details

Severity: Medium

ID: 328689

File Name: suse_SU-2026-3137-1.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 7/21/2026

Updated: 7/21/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.9

Percentile: 96.92

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:N/A:N

CVSS Score Source: CVE-2026-11786

CVSS v3

Risk Factor: Medium

Base Score: 6.5

Temporal Score: 5.7

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:novell:suse_linux:15, p-cpe:/a:novell:suse_linux:389-ds-devel, p-cpe:/a:novell:suse_linux:389-ds, p-cpe:/a:novell:suse_linux:lib389, p-cpe:/a:novell:suse_linux:libsvrcore0

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 7/20/2026

Vulnerability Publication Date: 6/8/2026

Reference Information

CVE: CVE-2026-11610, CVE-2026-11611, CVE-2026-11774, CVE-2026-11785, CVE-2026-11786, CVE-2026-11787, CVE-2026-11788, CVE-2026-11789, CVE-2026-11790, CVE-2026-11791, CVE-2026-11792, CVE-2026-11793, CVE-2026-11884, CVE-2026-12528

SuSE: SUSE-SU-2026:3137-1