Linuxsecurity
openSUSE 389-ds Heap Overflow Vulnerabilities Lead to DoS Risks
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
openSUSE has released updates for the 389-ds directory server to address multiple vulnerabilities, including heap buffer overflows and memory growth issues. The vulnerabilities, identified as CVE-2026-11610, CVE-2026-11611, CVE-2026-11774, CVE-2026-11785, CVE-2026-11786, and CVE-2026-11787, affect versions 2.2.10~git255.752643c78. Attack vectors include specially crafted LDAP UNBIND packets and crafted SASL packet length prefixes, potentially leading to denial of service and information disclosure. The vulnerabilities were published between June 9 and July 7, 2026, with the latest advisory released on July 21, 2026. Affected systems include SUSE Linux Enterprise Server and openSUSE Leap across various architectures. Administrators are urged to apply the patches promptly to mitigate risks.
Key Points: • Multiple heap overflow vulnerabilities in openSUSE 389-ds could lead to DoS. • CVE-2026-11610 and CVE-2026-11611 are among the critical issues addressed. • Patches are available for various SUSE Linux Enterprise and openSUSE versions.