Skip to content
openSUSE 389-ds Heap Overflow Vulnerabilities Lead to DoS Risks

openSUSE 389-ds Heap Overflow Vulnerabilities Lead to DoS Risks

First seen 21 Jul 2026, 09:36 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster July 22, 2026 at 06:39 UTC
  • Multiple heap overflow vulnerabilities in openSUSE 389-ds could lead to DoS.
  • CVE-2026-11610 and CVE-2026-11611 are among the critical issues addressed.
  • Patches are available for various SUSE Linux Enterprise and openSUSE versions.

openSUSE has released updates for the 389-ds directory server to address multiple vulnerabilities, including heap buffer overflows and memory growth issues. The vulnerabilities, identified as CVE-2026-11610, CVE-2026-11611, CVE-2026-11774, CVE-2026-11785, CVE-2026-11786, and CVE-2026-11787, affect versions 2.2.10~git255.752643c78. Attack vectors include specially crafted LDAP UNBIND packets and crafted SASL packet length prefixes, potentially leading to denial of service and information disclosure. The vulnerabilities were published between June 9 and July 7, 2026, with the latest advisory released on July 21, 2026. Affected systems include SUSE Linux Enterprise Server and openSUSE Leap across various architectures. Administrators are urged to apply the patches promptly to mitigate risks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 51d ago How this analysis works

Timeline

2026-06-08
CVE-2026-11611 published
A memory growth issue in the Content Synchronization plugin was disclosed, affecting authenticated clients.
Linuxsecurity
2026-06-09
CVE-2026-11786 published
An out-of-bounds read vulnerability in the LDIF parser was disclosed, affecting 389-ds.
Linuxsecurity
2026-06-09
CVE-2026-11785 published
A type confusion issue in the SSO token handler was disclosed, leading to potential information disclosure.
Linuxsecurity
2026-06-09
CVE-2026-11787 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-11
CVE-2026-11774 published
An integer overflow vulnerability in sasl_io_start_packet() was disclosed, leading to heap buffer overflow risks.
Linuxsecurity
2026-07-07
CVE-2026-11610 published
A missing bounds check in sasl_io_recv() was disclosed, leading to heap buffer overflow risks.
Linuxsecurity
2026-07-21
openSUSE releases patch for 389-ds vulnerabilities
SUSE released updates to address multiple vulnerabilities in 389-ds, urging immediate patching.
Linuxsecurity

More articles in this cluster (3)

Following this threat?

Track CVE-2026-11610 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed