[CLSA-2026:1777310722] openldap: Fix of 15 CVEs
Type:
security
Severity:
Important
Release date:
2026-04-27 17:25:27 UTC
Description:
- CVE-2019-13565: SASL session encryption SSF not reset on new connection, allowing downgrade - CVE-2020-12243: slapd crash via deeply nested LDAP search filter boolean expressions - CVE-2020-25692: NULL pointer dereference in slapd during modRDN request - CVE-2020-25709: slapd assertion failure via crafted certificate list validation - CVE-2020-25710: slapd assertion failure in obsolete csnNormalize23 - CVE-2020-36221: slapd integer underflow crash in Certificate Exact Assertion processing - CVE-2020-36222: slapd assertion failure in saslAuthzTo validation - CVE-2020-36223: slapd double free crash in Values Return Filter control handling - CVE-2020-36224: slapd invalid pointer free and crash in saslAuthzTo processing - CVE-2020-36225: slapd double free crash in saslAuthzTo processing - CVE-2020-36226: slapd memch->bv_len miscalculation and crash in saslAuthzTo processing - CVE-2020-36227: slapd infinite loop via cancel_extop Cancel operation - CVE-2020-36228: slapd integer underflow crash in Certificate List Exact Assertion processing - CVE-2020-36229: slapd crash in X.509 DN parsing ad_keystring via ldap_X509dn2bv - CVE-2020-36230: slapd assertion failure in X.509 DN parsing ber_next_element in decode.c
Updated packages:
  • openldap-2.4.46-18.el8.tuxcare.els4.i686.rpm
    sha:c422327ef25a7a5771c633a8663bf775ba09a22a74a472aeaa2019dbb08f377b
  • openldap-2.4.46-18.el8.tuxcare.els4.x86_64.rpm
    sha:c0afff6544222ce78bcdd22089dccf23b24fb6566bafef88940b9b9aed3b1adb
  • openldap-clients-2.4.46-18.el8.tuxcare.els4.x86_64.rpm
    sha:d82a0f302fd3537155c08ed6854efbf2d85dd217bfd5eb123e436d0828e25f82
  • openldap-devel-2.4.46-18.el8.tuxcare.els4.i686.rpm
    sha:47fc3e56d8bc35c22c5133b963d6c4785b9a7fbb22e8b99fa42015dc296226d9
  • openldap-devel-2.4.46-18.el8.tuxcare.els4.x86_64.rpm
    sha:fe01e4d2ae0a2c15cfeddc88cb88d6706749608763e0f4f2e33c763ba8b8eb4d
  • openldap-servers-2.4.46-18.el8.tuxcare.els4.x86_64.rpm
    sha:d3a38d7acdb86782cb8bf89ccad3e509d9452f0dedcdd20c5bf56ddb0fa938b1
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.