Critical Vulnerabilities in openSUSE 389-ds Require Immediate Attention

Critical Vulnerabilities in openSUSE 389-ds Require Immediate Attention

First seen 24 Aug 2026, 16:53 UTC Linuxsecurity 60.8

Article Content

Browse articles
ThreatCluster

Recent updates to openSUSE's 389-ds have addressed several critical vulnerabilities, including CVE-2026-11774, which involves an integer overflow leading to a heap buffer overflow. This flaw can be exploited through SASL packet manipulation, potentially allowing attackers to execute arbitrary code. Other vulnerabilities include CVE-2026-11785, which can lead to partial stack address information disclosure, and CVE-2026-11786, which allows for out-of-bounds reads. These vulnerabilities affect various versions of SUSE Linux Enterprise Server and openSUSE Leap. The updates were released on August 21, 2026, and users are urged to apply patches immediately to mitigate risks. The vulnerabilities have been rated as important, indicating a significant threat to system integrity and confidentiality. The patches are available through standard installation methods like YaST and zypper.

Key Points: • Three critical vulnerabilities in openSUSE 389-ds require immediate patching. • CVE-2026-11774 allows for remote code execution via SASL packet manipulation. • Affected systems include SUSE Linux Enterprise Server and openSUSE Leap versions.

Timeline

2026-06-09
CVE-2026-11785 published
CVE-2026-11785 disclosed, allowing partial stack address information disclosure.
Linuxsecurity
2026-06-09
CVE-2026-11786 published
CVE-2026-11786 published, which can cause out-of-bounds reads.
Linuxsecurity
2026-06-11
CVE-2026-11774 published
CVE-2026-11774 disclosed, leading to a heap buffer overflow via SASL packet length overflow.
Linuxsecurity
2026-08-21
Patches released for vulnerabilities
SUSE released patches addressing the critical vulnerabilities in 389-ds.
Linuxsecurity
2026-08-24
Security advisories published
Multiple advisories released detailing the vulnerabilities and patch instructions.
Linuxsecurity