Monday, September 14, 2026

[389-users] Re: Security updates required for recent 389 Directory Server releases

Hi Viktor, Version 2.2.11 is not available in the COPR repo. I'm still confused about the current state of packages. 2.2.9 appears to still be the latest version of 389DS for Rocky 8/9, when using the instructions on this page: https://www.port389.org/docs/389ds/download.html Based upon your email, shouldn't that repo offer at least 2.2.11? Thanks in advance for your advice, -Bryan On Thu, Sep 10, 2026 at 01:38:34PM +0200, Viktor Ashirov via 389-users wrote: > Hello, > > The 389 Directory Server team published security updates for multiple > release branches: > > - 3.3.1 (https://www.port389.org/docs/389ds/releases/release-3-3-1.html) > - 3.2.3 (https://www.port389.org/docs/389ds/releases/release-3-2-3.html) > - 3.1.5 (https://www.port389.org/docs/389ds/releases/release-3-1-5.html) > - 3.0.7 (https://www.port389.org/docs/389ds/releases/release-3-0-7.html) > - 2.9.1 (https://www.port389.org/docs/389ds/releases/release-2-9-1.html) > - 2.8.2 (https://www.port389.org/docs/389ds/releases/release-2-8-2.html) > - 2.6.3 (https://www.port389.org/docs/389ds/releases/release-2-6-3.html) > - 2.4.7 (https://www.port389.org/docs/389ds/releases/release-2-4-7.html) > - 2.2.11 (https://www.port389.org/docs/389ds/releases/release-2-2-11.html) > - 1.4.3.41 ( > https://www.port389.org/docs/389ds/releases/release-1-4-3-41.html) > > These releases address multiple security vulnerabilities, including > remotely exploitable issues such as: > - CVE-2026-18922 <https://access.redhat.com/security/cve/CVE-2026-18922> - > 9.8 Critical > - CVE-2026-19843 <https://access.redhat.com/security/cve/CVE-2026-19843> - > 8.4 Important > - CVE-2026-11770 <https://access.redhat.com/security/cve/CVE-2026-11770> - > 7.5 Moderate > - CVE-2026-18355 <https://access.redhat.com/security/cve/CVE-2026-18355> - > 7.5 Important > - CVE-2026-18453 <https://access.redhat.com/security/cve/CVE-2026-18453> - > 7.5 Important > - CVE-2026-76560 <https://access.redhat.com/security/cve/CVE-2026-76560> - > 7.5 Important > - CVE-2026-9064 <https://access.redhat.com/security/cve/CVE-2026-9064> - > 7.5 Important > > Please treat this as a critical security update. Review your installed > version and upgrade to the latest applicable release as soon as possible. > > Regards, > The 389 Directory Server team > -- > _______________________________________________ > 389-users mailing list -- 389-users@lists.fedoraproject.org > To unsubscribe send an email to 389-users-leave@lists.fedoraproject.org > Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ > List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines > List Archives: https://lists.fedoraproject.org/archives/list/389-users@lists.fedoraproject.org > Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new -- Bryan K. Walton 319-337-3877 Senior Linux Systems Administrator Leepfrog Technologies, Inc -- _______________________________________________ 389-users mailing list -- 389-users@lists.fedoraproject.org To unsubscribe send an email to 389-users-leave@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/389-users@lists.fedoraproject.org Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new

No comments:

Post a Comment