Updated 389-ds-base packages fix a security vulnerability
Publication date: 30 Jul 2026Modification date: 30 Jul 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-9064
Description
The updated packages fix a security vulnerability:
Unbounded ldap controls count in get_ldapmessage_controls_ext() causes
cpu and heap amplification (remote dos). (CVE-2026-9064)
References
- https://bugs.mageia.org/show_bug.cgi?id=35838
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HGVVCWTZBWDJ7HSAGE646TODMKUK56FR/
- https://bugzilla.redhat.com/show_bug.cgi?id=2480093
- https://github.com/389ds/389-ds-base/issues/7503
- https://www.cve.org/CVERecord?id=CVE-2026-9064
SRPMS
10/core
- 389-ds-base-3.1.3-2.1.mga10