Bug#1144474: 389-ds-base: CVE-2026-19404

Salvatore Bonaccorso <[email protected]>
Newsgroups gmane.linux.debian.devel.bugs.rc
Message-ID <178680541118.1665850.5663504884643401722.reportbug__3400.23535988934$1786805596$gmane$org@eldamar.lan>
Source: 389-ds-base
Version: 3.3.0-2
Severity: grave
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for 389-ds-base.

Unfortunately there are upstream references provided, at time of
writing only the Red Hat bugzilla entry so far.

CVE-2026-19404[0]:
| A flaw was found in 389 Directory Server. The CleanAllRUV and Abort
| CleanAllRUV replication-maintenance extended operations perform no
| authorization check, allowing an unauthenticated remote attacker to
| invoke them when nsslapd-allow-anonymous-access is enabled (the
| default), or any authenticated low-privilege user to invoke them
| otherwise. This allows removal of a replica ID from replication
| metadata, purging of changelog records, and interruption of
| administrator-initiated cleanup, which can leave replication
| inconsistent or unavailable.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-19404
    https://www.cve.org/CVERecord?id=CVE-2026-19404
[1] https://bugzilla.redhat.com/show_bug.cgi?id=2513036

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.