Your message dated Wed, 05 Aug 2026 14:23:18 +0000
with message-id <[email protected]>
and subject line Bug#1137436: fixed in 389-ds-base 3.3.0-1
has caused the Debian Bug report #1137436,
regarding 389-ds-base: CVE-2026-9064
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1137436: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1137436
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: 389-ds-base
Version: 3.1.2+vendor1-2
Severity: grave
Tags: security upstream
Justification: user security hole
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerability was published for 389-ds-base.
CVE-2026-9064[0]:
| A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext()
| function in the LDAP server does not enforce an upper bound on the
| number of controls per LDAP message. A remote, unauthenticated
| attacker can send a specially crafted LDAP request containing
| hundreds of thousands of minimal controls within the default maximum
| BER message size (2 MB), causing excessive CPU consumption and heap
| allocation on the server. Under concurrent exploitation, this leads
| to significant latency degradation, worker thread starvation, or
| out-of-memory termination, resulting in a denial of service.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-9064
https://www.cve.org/CVERecord?id=CVE-2026-9064
[1] https://github.com/389ds/389-ds-base/issues/7503
[2]
https://github.com/389ds/389-ds-base/commit/7e9647f5bb5c47602f4cdf0022cf6bd22872d3ef
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: 389-ds-base
Source-Version: 3.3.0-1
Done: Timo Aaltonen <[email protected]>
We believe that the bug you reported is fixed in the latest version of
389-ds-base, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Timo Aaltonen <[email protected]> (supplier of updated 389-ds-base package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Wed, 05 Aug 2026 16:52:55 +0300
Source: 389-ds-base
Built-For-Profiles: derivative.ubuntu noudeb
Architecture: source
Version: 3.3.0-1
Distribution: unstable
Urgency: medium
Maintainer: Debian FreeIPA Team <[email protected]>
Changed-By: Timo Aaltonen <[email protected]>
Closes: 1137436
Changes:
389-ds-base (3.3.0-1) unstable; urgency=medium
.
* New upstream release.
- CVE-2026-9064 (Closes: #1137436)
* patches: Drop upstreamed patches.
* watch: Updated.
* Migrate to pybuild.
* patches: Fix nss includes.
* Include a read-only implementation derived from rpm (librobdb.so).
* rules: Don't clean Cargo.toml.orig-files.
* control: Drop python3-packaging from (build-)depends.
* control: Drop unnecessary direct python dependencies from python3-
lib389.
* Drop old vendoring cruft.
* fix-nss-include.diff: Dropped, obsolete.
Checksums-Sha1:
27c91491f44168b26de21bee2fc2843923b6b2fb 2837 389-ds-base_3.3.0-1.dsc
3c97a4b592912804ec0fa330eaf639fe52b3076f 23841623
389-ds-base_3.3.0.orig.tar.bz2
4128a0cca0ab3aaab772b30ea038e2fb75eb91e8 26200
389-ds-base_3.3.0-1.debian.tar.xz
255b9da16ab9e2e2aacd5e841fbf0418e0a7b4af 11127
389-ds-base_3.3.0-1_source.buildinfo
Checksums-Sha256:
ff82a8ae1d0b80eb2e0786cc4bb9ffdd25194fc3d8bd82570a6c4b52b7738bcf 2837
389-ds-base_3.3.0-1.dsc
68b856bf7b231701cb9c740b04a7bb52f4841fa729f1b7f20bb069ef6f665b59 23841623
389-ds-base_3.3.0.orig.tar.bz2
af0c162b9b788fba63dc4cd96fcc68da914dbaaac21e27c74643e22351587cfb 26200
389-ds-base_3.3.0-1.debian.tar.xz
af017157bd5f7cb77304b7c5d7c50481518f7d8ce2fab51f06fb807d8ea0a6d6 11127
389-ds-base_3.3.0-1_source.buildinfo
Files:
0d2886bd5989f00a55a491645811b5ef 2837 net optional 389-ds-base_3.3.0-1.dsc
51f6d942da2bb9c67fd9f22304db47d9 23841623 net optional
389-ds-base_3.3.0.orig.tar.bz2
12369962e3b3585ed09dccd4152bdd8a 26200 net optional
389-ds-base_3.3.0-1.debian.tar.xz
2f900776ee88af2c43aa14a47d5a50ef 11127 net optional
389-ds-base_3.3.0-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEdS3ifE3rFwGbS2Yjy3AxZaiJhNwFAmpzQHAACgkQy3AxZaiJ
hNwdoQ//S1Zkf+ncPiQI5sSuKlxxDLYni0O7Te6h5wohZ4+vXxgG6UyaRuiLoob7
pjPvREc2lXVpGiMocks9IYq0/69240LP3TgjD6VfAwvwGsj9WcKigZ572NqX1k7X
bEZhnNi/mjZbaXiGq2+LUtli2Gt9U9s6i6HbzzZOsnJJYd5DUm2UupRodk0phu5s
vQkdKyhGdLEv2Nbx2awYRJoAv/HnHRhc0DmCWlW1/RceQGxT0SpKNfN14yoZzMeV
y+HoL7wJclJmPKcZxOUNXamThkM8ALaShFLvwmL96wEv72/wLBeQ6VqRvuC/zbI/
6HDKnRm4Nhl6MK9//R8jEtcAMs26eTcTaje5VtxocIsK0t72L0175U1Mqd4gFatR
Quv3hXrjvBNcjNrTycCu34v3CBM7n9o+Z+Cr4cLOcNQCiFx8d8NiJJzKLvPz1zlK
hwyA1FOYpzsE7BYpH5FVcpbQr3NPGvWcA+dr4QHzW8tKPz8Byno8THlUE7pMHRbX
lHsxyHQy0CmYJN7vI78z6UQDE2MemnBwscipZmsRuWBGXtiLl96z9nUBlNPruabd
er48Rn4kYhCwGLAkTyCP8DleghcYUVYV8oasxRWHQjAOZBIODk87sG3hTRLSMFkN
/SSfWxtPUesZxE5fLZioc6MJI7mbfm08NtyYut1iwE3rEo40sS0=
=bLDp
-----END PGP SIGNATURE-----
pgpcMd9THhaKf.pgp
Description: PGP signature
--- End Message ---