-
Mon Aug 31 2026 Viktor Ashirov <vashirov@redhat.com> - 2.8.0-10
- Resolves: RHEL-220502 - CVE-2026-18355 389-ds-base: heap buffer overflow via SASL wrapped-record length lower-bound underflow in sasl_io_start_packet() [rhel-9.8.z]
- Resolves: RHEL-222321 - CVE-2026-18453 389-ds-base: pre-authentication NULL pointer dereference via paged results and USE_ONE_BACKEND control in op_shared_search [rhel-9.8.z]
- Resolves: RHEL-232854 - CVE-2026-18922 389-ds-base: SASL PLAIN authentication allows privilege escalation to Directory Manager via stale identity in Cyrus SASL auxiliary property [rhel-9.8.z]
- Resolves: RHEL-244467 - lib389: set nsDS5ReplicaBindDNGroup before ensure_agreement() [rhel-9.8.z]
- Resolves: RHEL-245374 - CVE-2026-76560 389-ds-base: anonymous LDAP client can defeat SELFDN ACI bind-rule checks via empty bind DN [rhel-9.8.z]
- Resolves: RHEL-247865 - CVE-2026-78701 389-ds-base: CVE-2026-11610 incomplete fix may introduce a connection-stall DoS [rhel-9.8.z]
- Resolves: RHEL-248766 - CVE-2026-11770 fix breaks replication total init when nsDS5ReplicaBindDNGroup is set after agreement creation [rhel-9.8.z]
-
Mon Jul 27 2026 Viktor Ashirov <vashirov@redhat.com> - 2.8.0-9
- Resolves: RHEL-183082 - CVE-2026-11770 389-ds-base: 389-ds-base: pre-auth LDAP filter injection in CleanAllRUV status check [rhel-9.8.z]
- Resolves: RHEL-190775 - CVE-2026-11788 389-ds-base: 389-ds-base: NULL pointer dereference in deref control plugin BER parser [rhel-9.8.z]
- Resolves: RHEL-210875 - CVE-2026-15722 389-ds-base: 389-ds-base: pre-authentication stack buffer overflow in get_ruvelement_from_berval() via unbounded replica ID parsing [rhel-9.8.z]
-
Thu Jun 25 2026 Viktor Ashirov <vashirov@redhat.com> - 2.8.0-8
- Resolves: RHEL-182159 - CVE-2026-11610 389-ds-base: 389-ds-base: Heap buffer overflow in sasl_io_recv() via padded SASL UNBIND [rhel-9.8.z]
- Resolves: RHEL-183103 - CVE-2026-11774 389-ds-base: 389-ds-base: integer overflow in SASL packet length bypasses size limit leading to heap buffer overflow [rhel-9.8.z]
-
Thu Jun 11 2026 Viktor Ashirov <vashirov@redhat.com> - 2.8.0-7
- Resolves: RHEL-152356 - Getting "build_candidate_list - Database error 11" messages after migrating to LMDB. [rhel-9.8.z]
- Resolves: RHEL-168967 - Web console doesn't show the sub suffix of ou=foo,ou=people,dc=example,dc=com. [rhel-9.8.z]
- Resolves: RHEL-170269 - DS 12 does not handle escape char in bind user [rhel-9.8.z]
- Resolves: RHEL-174524 - [RFE] Add OS-level thread names to all server threads [rhel-9.8.z]
- Resolves: RHEL-178086 - CVE-2026-9064 389-ds-base: 389-ds-base: unbounded LDAP controls count in get_ldapmessage_controls_ext() causes CPU and heap amplification (remote DoS) [rhel-9.8]
- Resolves: RHEL-180716 - Online export is failing when using the option "-s" [rhel-9.8.z]
- Resolves: RHEL-183895 - Server shutdown during online reindex may lead to data loss [rhel-9.8.z]
-
Thu Mar 05 2026 Viktor Ashirov <vashirov@redhat.com> - 2.8.0-6
- Resolves: RHEL-152335 - Crash in trim_changelog() during the Retro Changelog trimming. [rhel-9.8]
-
Fri Feb 27 2026 Viktor Ashirov <vashirov@redhat.com> - 2.8.0-5
- Resolves: RHEL-137084 - CVE-2025-14905 389-ds-base: 389-ds-base: Remote Code Execution and Denial of Service via heap buffer overflow [rhel-9.8]
- Resolves: RHEL-152335 - Crash in trim_changelog() during the Retro Changelog trimming. [rhel-9.8]
- Resolves: RHEL-152338 - Crash ( Segmentation fault ) in atomic_compare_exchange() [rhel-9.8]
-
Fri Feb 20 2026 Viktor Ashirov <vashirov@redhat.com> - 2.8.0-4
- Resolves: RHEL-117050 - Replication online reinitialization of a large database gets stalled. [rhel-9]
- Resolves: RHEL-123279 - The new ipahealthcheck test ipahealthcheck.ds.backends.BackendsCheck raises CRITICAL issue [rhel-9]
- Resolves: RHEL-140275 - ipa-healthcheck is complaining about missing or incorrectly configured system indexes. [rhel-9]
- Resolves: RHEL-142980 - Scalability issue of replication online initialization with large database [rhel-9]
- Resolves: RHEL-146899 - memory corruption in alias entry plugin [rhel-9]
- Resolves: RHEL-147212 - Access logs are not getting deleted as configured. [rhel-9]
- Resolves: RHEL-150907 - Remove memberof_del_dn_from_groups from MemberOf plugin [rhel-9]
-
Thu Feb 12 2026 Viktor Ashirov <vashirov@redhat.com> - 2.8.0-3
- Resolves: RHEL-117050 - Replication online reinitialization of a large database gets stalled. [rhel-9]
- Resolves: RHEL-123244 - Attribute uniqueness is not enforced upon modrdn operation [rhel-9]
- Resolves: RHEL-123279 - The new ipahealthcheck test ipahealthcheck.ds.backends.BackendsCheck raises CRITICAL issue [rhel-9]
- Resolves: RHEL-140275 - ipa-healthcheck is complaining about missing or incorrectly configured system indexes. [rhel-9]
- Resolves: RHEL-142980 - Scalability issue of replication online initialization with large database [rhel-9]
- Resolves: RHEL-146899 - memory corruption in alias entry plugin [rhel-9]
- Resolves: RHEL-147212 - Access logs are not getting deleted as configured. [rhel-9]
-
Mon Jan 12 2026 Viktor Ashirov <vashirov@redhat.com> - 2.8.0-2
- Resolves: RHEL-140089 - Upgrading IDM to latest version: 389-ds-base and ipa-server breaks replication [rhel-9]
-
Fri Jan 09 2026 Viktor Ashirov <vashirov@redhat.com> - 2.8.0-1
- Resolves: RHEL-111229 - Error showing local password policy on web UI [rhel-9]
- Resolves: RHEL-112680 - Statistics about index lookup report a wrong duration [rhel-9]
- Resolves: RHEL-116426 - RetroCL plugin generates invalid LDIF [rhel-9]
- Resolves: RHEL-117050 - Replication online reinitialization of a large database gets stalled. [rhel-9]
- Resolves: RHEL-117748 - The numSubordinates value is not matching the number of direct children. [rhel-9]
- Resolves: RHEL-117771 - When deferred memberof update is enabled after the server crashed it should not launch memberof fixup task by default
- Resolves: RHEL-117782 - Ignore the memberOfDeferredUpdate setting when LMDB is used. [rhel-9]
- Resolves: RHEL-121170 - Units for changing MDB max size are not consistent across different tools [rhel-9]
- Resolves: RHEL-123231 - Improve the way to detect asynchronous operations in the access logs [rhel-9]
- Resolves: RHEL-123244 - Attribute uniqueness is not enforced upon modrdn operation [rhel-9]
- Resolves: RHEL-123258 - Typo in errors log after a Memberof fixup task. [rhel-9]
- Resolves: RHEL-123272 - LDAP high CPU usage while handling indexes with IDL scan limit at INT_MAX [rhel-9]
- Resolves: RHEL-123279 - The new ipahealthcheck test ipahealthcheck.ds.backends.BackendsCheck raises CRITICAL issue [rhel-9]
- Resolves: RHEL-123368 - IPA health check up script shows time skew is over 24 hours [rhel-9]
- Resolves: RHEL-123766 - 389-ds-base OpenScanHub Leaks Detected [rhel-9]
- Resolves: RHEL-123893 - Improve output dsctl dbverify when backend does not exist [rhel-9]
- Resolves: RHEL-123897 - [WebUI] Replication tab crashes after enabling replication as a consumer [rhel-9]
- Resolves: RHEL-123923 - Changelog trimming - add number of scanned entries to the log [rhel-9]
- Resolves: RHEL-126552 - RHDS 12.6 doesn't handle 'ldapsearch' filter with space char in DN name correctly [rhel-9]
- Resolves: RHEL-129559 - Online initialization of consumers fails with error -23 [rhel-9]
- Resolves: RHEL-129580 - Fix paged result search locking [rhel-9]
- Resolves: RHEL-138481 - Memory leak observed in ns-slapd with 389-ds-base-2.6.1-12 [rhel-9]
- Resolves: RHEL-139825 - Rebase 389-ds-base to 2.8.x
- Resolves: RHEL-140089 - Upgrading IDM to latest version: 389-ds-base and ipa-server breaks replication [rhel-9]