openSUSE 389-ds Heap Overflow Vulnerabilities Lead to DoS Risks

openSUSE 389-ds Heap Overflow Vulnerabilities Lead to DoS Risks

First seen 21 Jul 2026, 09:36 UTC Linuxsecurity 99% similarity 70.5

Article Content

Browse articles
ThreatCluster

openSUSE has released updates for the 389-ds directory server to address multiple vulnerabilities, including heap buffer overflows and memory growth issues. The vulnerabilities, identified as CVE-2026-11610, CVE-2026-11611, CVE-2026-11774, CVE-2026-11785, CVE-2026-11786, and CVE-2026-11787, affect versions 2.2.10~git255.752643c78. Attack vectors include specially crafted LDAP UNBIND packets and crafted SASL packet length prefixes, potentially leading to denial of service and information disclosure. The vulnerabilities were published between June 9 and July 7, 2026, with the latest advisory released on July 21, 2026. Affected systems include SUSE Linux Enterprise Server and openSUSE Leap across various architectures. Administrators are urged to apply the patches promptly to mitigate risks.

Key Points: • Multiple heap overflow vulnerabilities in openSUSE 389-ds could lead to DoS. • CVE-2026-11610 and CVE-2026-11611 are among the critical issues addressed. • Patches are available for various SUSE Linux Enterprise and openSUSE versions.

ThreatCluster AI

Timeline

2026-06-08
CVE-2026-11611 published
A memory growth issue in the Content Synchronization plugin was disclosed, affecting authenticated clients.
Linuxsecurity
2026-06-09
CVE-2026-11786 published
An out-of-bounds read vulnerability in the LDIF parser was disclosed, affecting 389-ds.
Linuxsecurity
2026-06-09
CVE-2026-11785 published
A type confusion issue in the SSO token handler was disclosed, leading to potential information disclosure.
Linuxsecurity
2026-06-09
CVE-2026-11787 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-11
CVE-2026-11774 published
An integer overflow vulnerability in sasl_io_start_packet() was disclosed, leading to heap buffer overflow risks.
Linuxsecurity
2026-07-07
CVE-2026-11610 published
A missing bounds check in sasl_io_recv() was disclosed, leading to heap buffer overflow risks.
Linuxsecurity
2026-07-21
openSUSE releases patch for 389-ds vulnerabilities
SUSE released updates to address multiple vulnerabilities in 389-ds, urging immediate patching.
Linuxsecurity

Community

Browse all →