[CLSA-2026:1777393215] openldap: Fix of 15 CVEs
Type:
security
Severity:
Important
Release date:
2026-04-28 16:20:21 UTC
Description:
- CVE-2019-13565: SASL session encryption SSF not reset on new connection, allowing downgrade - CVE-2020-12243: slapd crash via deeply nested LDAP search filter boolean expressions - CVE-2020-25692: NULL pointer dereference in slapd during modRDN request - CVE-2020-25709: slapd assertion failure via crafted certificate list validation - CVE-2020-25710: slapd assertion failure in obsolete csnNormalize23 - CVE-2020-36221: slapd integer underflow crash in Certificate Exact Assertion processing - CVE-2020-36222: slapd assertion failure in saslAuthzTo validation - CVE-2020-36223: slapd double free crash in Values Return Filter control handling - CVE-2020-36224: slapd invalid pointer free and crash in saslAuthzTo processing - CVE-2020-36225: slapd double free crash in saslAuthzTo processing - CVE-2020-36226: slapd memch->bv_len miscalculation and crash in saslAuthzTo processing - CVE-2020-36227: slapd infinite loop via cancel_extop Cancel operation - CVE-2020-36228: slapd integer underflow crash in Certificate List Exact Assertion processing - CVE-2020-36229: slapd crash in X.509 DN parsing ad_keystring via ldap_X509dn2bv - CVE-2020-36230: slapd assertion failure in X.509 DN parsing ber_next_element in decode.c
Updated packages:
  • openldap-2.4.46-17.el8_4.tuxcare.els4.i686.rpm
    sha:3ea7644150daabc7203bcdf0e8382848a4eb12ec6d18df6f28943401a5518608
  • openldap-2.4.46-17.el8_4.tuxcare.els4.x86_64.rpm
    sha:b722ebf258aa1397961818531d2b25773ddbfa18d73e002dd5f72e5b14875483
  • openldap-clients-2.4.46-17.el8_4.tuxcare.els4.x86_64.rpm
    sha:547a909bff051bcbcc717bd2052c591dfc93af4491af42f25990439858374ba7
  • openldap-devel-2.4.46-17.el8_4.tuxcare.els4.i686.rpm
    sha:c4af915dbc82a09cf3fab9738dd2efa9fe0af3e70b6bc6b290cd0e1f98b41428
  • openldap-devel-2.4.46-17.el8_4.tuxcare.els4.x86_64.rpm
    sha:821cda2a5b40890df523811921d49106e5a262a1ab150228455b970b4346eb1e
  • openldap-servers-2.4.46-17.el8_4.tuxcare.els4.x86_64.rpm
    sha:6690fe8af7601f692d5ba6e8dbed73711c88fa4d97c20b3f5df3262db1fe5a86
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.