389 Directory Server 1.4.3.41
The 389 Directory Server team is proud to announce 389-ds-base version 1.4.3.41.
The new package and version is:
Source tarball: GitHub Releases
Highlights in 1.4.3.41
- Security fixes for CVE-2024-8445, CVE-2025-14905, CVE-2026-11770, CVE-2026-18355, CVE-2026-18453, CVE-2026-18922, CVE-2026-19843, CVE-2026-76560, CVE-2026-9064.
- Fix memory-safety issues in retro changelog, SASL, LDAP parsing, ACL processing, and deferred MemberOf updates.
- Add
dsctl index-check, upgrade handling for index ordering, OS-level thread names, and work queue utilization metrics.
- Improve replication initialization, agreement creation, search locking, large-database indexing, and password policy handling.
See Download for package installation and Install Guide for setup.
Changelog between 389-ds-base-1.4.3.40 and 389-ds-base-1.4.3.41:
- Bump version to 1.4.3.41
- Security fix for CVE-2026-76560
- Security fix for CVE-2026-19843
- Security fix for CVE-2026-18922
- Security fix for CVE-2026-18453
- Security fix for CVE-2026-18355
- Issue 7595 - Remove the nightly dedup gate and fix dispatched test runs
- Fix startrepl_auth_race_test.py for lib389 API compatibility
- Issue 7774 - Add backport action #7775
- Issue 6963 - Add missing __init__.py files under webui #6964
- Issue 6960 - Add missing imports to import/regression_test.py. #6962
- Issue 7770 - Testimony failure in test_cleanruv_extop_security.py #7771
- CVE-2026-11770 - Fix StartReplicationRequest auth gate response format
- Security fix for CVE-2026-11770
- Issue 3082 - Add test389.topologies compatibility shim for backports #7725
- Issue 7595 - Skip redundant CI runs to relieve the Actions queue #7756
- Issue 4701 - Fix UAF when excluding attrs from retro changelog #7730
- Issue 7735 - Heap overflow when parsing objectclass superior #7736
- Issue 7733 - Typo about nsuniqueid in tombstone_to_conflict #7734
- Issue 7707 - lib389: set nsDS5ReplicaBindDNGroup before ensure_agreement() in join_supplier/hub/consumer #7708
- Issue 7645 - Add runtime LeakSanitizer leak check #7646
- Issue 7658 - Heap Buffer Overflow in sasl_io_recv() via Padded SASL UNBIND
- Issue 7710 - MemberOf deferred update - Use condvar instead of sleep loop
- Issue 7605 - Harden CI test ports against ephemeral allocation #7692
- Issue 7528 - Retry the CI image pull instead of failing the job #7691
- Issue 7460 - MOD_REPLACE on groups/link attributes modifies overlap targets #7461
- Issue 7108 - Fix shutdown crash in entry cache destruction #7163
- Issue 7284 - Creating local password policy succeeds with incorrect passwordInHistory value #7662
- Issue 7200 - repl-agmt create doesn’t set some parameters #7663
- Issue 7558 - Total init sends the suffix entry twice #7640
- Issue 7611 - Preserve legacy PBKDF2 hash compatibility #7649
- Issue 7547 - Heap buffer overflow in ldap_utf8prev()
- Issue 7611 - PBKDF2 password verification should reject invalid iteration count #7613
- Issue 7635 - Integer Underflow in {SMD5} Password Comparison #7636
- Issue 7558 - During online import, the IDL should be created with in-depth first approach #7559
- Issue 7406 - Fix ldap-agent SNMP stats file loading #7630
- Issue 7621 - Stack Buffer Overflow in Password checkPrefix
- Issue 7623 - Heap Buffer Overflow in 389-ds-base Audit Log Password Masking
- Issue 6625 - Backport get_pid to fix check_asan_report #7626
- Issue 7602 - CI - lib389 user compare fails due to parentid mismatch #7603
- Issue 7593 - Fix testimony docstring for SASL overflow test #7606
- Issue 7593 - Reject invalid SASL packet length values in sasl_io_start_packet #7594
- Issue 3555 - UI - Fix audit issue with npm - ws, js-yaml, js-yaml, postcss, uuid
- Issue 7576 - Fix leak of temporary attribute syntax hash tables after schema reload
- Revert “Issue 7558 - During online import, the IDL should be created with in-depth first approach #7559”
- Issue 7558 - During online import, the IDL should be created with in-depth first approach #7559
- Issue 7560 - lib389 - Add helper function for checking ASAN files
- Issue 7549 - Substring index should validate minimum nsSubStrBegin/nsSubStrEnd values #7550
- Issue 7440 - Substring index produces empty results and can crash when non-default nsSubStrBegin/nsSubStrEnd lengths are configured #7441
- Fix test389 imports on older branches
- Issue 7437 - LeakSanitizer: memory leaks in CoS cache error paths #7438
- Issue 6922 - AddressSanitizer: leaks found by acl test suite
- Issue 3555 - UI - Fix audit issue with npm - brace-expansion #7556
- Issue 7554 - deref plugin null pointer dereference if ber_init fails
- Issue 7503 - Fix test DN comparison to be case-insensitive #7557
- Issue 7503 - CVE-2026-9064 - Add a limit to the number controls per operation
- Issue 7271 - Fix build failure on 1.4.3
- Issue 7300 - RFE - Add OS-level thread names to all server threads #7301
- Issue 5947 - Do not release the target entry in ldbm_back_search_cleanup
- Issue 7307 - RFE - Expose work queue and worker utilization metrics #7308
- Issue 7457 - Refactor memberOf perf test #7458
- Issue 7417 - UI - global password policy syntax settings missing passwordMaxRepeats
- Issue 3555 - UI - Fix audit issue with npm - brace-expansion #7411
- Issue 7423 - cleanup pblock after freeing pre/post entries
- Issue 7418 - Use-after-free in deferred memberof #7419
- Issue 7277 - UI - Fix Japanese translation errors errors in Cockpit UI #7386
- Issue 7152 - ns-slapd fails to shutdown when deferred memberof update is in progress #7187
- Issue 7126 - WARN - keys2idl - received NULL idl from index_read_ext_allids #7127
- Issue 7370 - Runtime LSan/TSan injection for pytest #7371
- Issue 7380 - Internal op with negative wtime and large optime #7381
- Issue 7366 - Memory leaks in syncrepl plugin during persistent search operations #7367
- Issue 3555 - UI - Fix audit issue with npm - flatted, picomatch #7364
- Issue 1704 - DNA plugin creates invalid shared config entry with port 0 #7352
- Issue 6753 - Removing ticket 477828 test and porting to DSLdapObject #6989
- Issue 7346 - DS does not handle escape char in bind user #7347
- Issue 7342 - CI - repl config regression #7343
- Issue 7233 - test_produce_division_by_zero fails with IsADirectoryError in conftest.py #7234
- Issue 7271 - Add new plugin pre-close function check to plugin_invoke_plugin_pb
- Issue 7304 - retrocl should not cache DN
- Issue 3555 - UI - Fix audit issue with npm - ajv, minimatch #7298
- Issue 7271 - implement a pre-close plugin function
- Issue 7291 - Crash when configuring a replica with an incorrect nsds5ReplicaRoot #7292
- Issue 7284 - Creating local password policy succeeds with incorrect passwordInHistory value #7285
- Security fix for CVE-2025-14905
- Issue 7277 - UI - Fix Japanese translation for “Successfully updated group” in Cockpit UI #7278
- Issue 7275 - UI - Improve password policy field validation in Cockpit UI #7276
- Issue 7279 - UI - Fix typo in export certificate dialog #7280
- Issue 7273 - In a chaining environment binding as remote user causes an invalid error in the logs
- Issue 7271 - plugins that create threads need to update
- Issue 5853 - Update concread to 0.5.10
- Issue 7223 - Remove integerOrderingMatch requirement for parentid #7264
- Issue 7223 - Use lexicographical order for ancestorid
- Issue 7223 - Add dsctl index-check command for offline index repair
- Issue 7223 - Detect and log index ordering mismatch during backend startup
- Issue 7223 - Add upgrade function to remove ancestorid index config entry
- Issue 7223 - Add upgrade function to remove nsIndexIDListScanLimit from parentid
- Issue 7223 - Backport upgrade infrastructure from main branch
- Issue 7223 - Revert index scan limits for system indexes
- Issue - CLI - dsctl db2index needs some hardening with MBD
- Issue 7121 - (2nd) LeakSanitizer: various leaks during replication #7212
- Issue 6583 - Fix CI on older branches
- Issue 6583 - Fix CI on older branches #6584
- Issue 3555 - UI - Fix audit issue with npm - @isaacs/brace-expansion #7228
- Issue 7224 - CI Test - Simplify test_reserve_descriptor_validation #7225
- Issue 7198 - Web console doesn’t show sub-suffix when parent-suffix points to an entry #7202
- Issue 7189 - DSBLE0007 generates incorrect remediation commands for scan limits
- Bump lodash from 4.17.21 to 4.17.23 in /src/cockpit/389-console #7203
- Issue 7172 - (2nd) Index ordering mismatch after upgrade #7180
- Issue 7172 - Index ordering mismatch after upgrade #7173
- Issue - Revise paged result search locking
- Issue 7096 - During replication online total init the function idl_id_is_in_idlist is not scaling with large database #7145
- Issue 6846 - Attribute uniqueness is not enforced with modrdn #7026 #7130
- Issue 7119 - Fix DNA shared config replication test #7143
- Issue 7124 - (2nd) BDB cursor race condition with transaction isolation
- Issue 7124 - BDB cursor race condition with transaction isolation #7125
- Issue 6947 - (Cont) Revise time skew check in healthcheck tool and add
- Issue 7121 - LeakSanitizer: various leaks during replication #7122
- Issue 7109 - AddressSanitizer: SEGV ldap/servers/slapd/csnset.c:302 in csnset_dup #7114
- Issue 7056 - DSBLE0007 doesn’t generate remediation steps for missing indexes
- Issue 7119 - Harden DNA plugin locking for shared server list operations #7120
- Issue 6901 - Update changelog trimming logging - fix tests
- Issue 6933 - (Cont) When deferred memberof update is enabled after the server crashed it should not launch memberof fixup task by default
- Issue 6966 - (2nd) On large DB, unlimited IDL scan limit reduce the SRCH performance
- Issue 7007 - Improve paged result search locking
- Issue 3555 - UI - Fix audit issue with npm - glob #7107
- Issue 6846 - Attribute uniqueness is not enforced with modrdn #7026
- Issue 6901 - Update changelog trimming logging #7102
- Bump js-yaml from 4.1.0 to 4.1.1 in /src/cockpit/389-console #7097
- Issue 7069 - Fix error reporting in HAProxy trusted IP parsing #7094
- Issue 7055 - Online initialization of consumers fails with error -23 #7075
- Issue 7069 - Add Subnet/CIDR Support for HAProxy Trusted IPs #7070
- Issue 7065 - A search filter containing a non normalized DN assertion does not return matching entries #7068
- Issue 7071 - search filter (&(cn:dn:=groups)) no longer returns results
- Issue 7073 - Add NDN cache size configuration and enforcement tests #7074
- Issue 7061 - CLI/UI - Improve error messages for dsconf localpwp list
- Issue 7059 - UI - unable to upload pem file
- Issue 6947 - Revise time skew check in healthcheck tool and add option
- Issue 7032 - The new ipahealthcheck test ipahealthcheck.ds.backends.BackendsCheck raises CRITICAL issue #7036
- Issue 7047 - MemberOf plugin logs null attribute name on fixup task completion #7048
- Issue 6979 - Improve the way to detect asynchronous operations in the access logs #6980
- Issue - CLI/UI - Add option to delete all replication conflict entries
- Issue 7033 - lib389 - basic plugin status not in JSON
- Issue 6966 - On large DB, unlimited IDL scan limit reduce the SRCH performance #6967
- Issue 6954 - do not delete referrals on chain_on_update backend
- Issue 6848 - AddressSanitizer: leak in do_search
- Issue 6928 - The parentId attribute is indexed with improper matching rule
- Issue 6933 - When deferred memberof update is enabled after the server crashed it should not launch memberof fixup task by default #6935
- Issue 7012 - improve dscrl dbverify result when backend does not exists #7013
- Issue 6929 - Compilation failure with rust-1.89 on Fedora ELN
- Issue 6641 - Fix memory leaks
- Issue 6940 - dsconf monitor server fails with ldapi:// due to absent server ID #6941
- Issue 6936 - Make user/subtree policy creation idempotent #6937
- Issue 6917 - dsconf config add fails with ‘_config_display_ldapimaprootdn_warning’ is not defined
- Issues 6913, 6886, 6250 - Adjust xfail marks #6914
- Issue 6897 - Fix disk monitoring test failures and improve test maintainability #6898
- Issue 6884 - Mask password hashes in audit logs #6885
- Issue 6594 - Add test for numSubordinates replication consistency with tombstones #6862
- Issue 6250 - Add test for entryUSN overflow on failed add operations #6821
- Issue 6895 - Crash if repl keep alive entry can not be created
- Issue 6893 - Log user that is updated during password modify extended operation
- Issue 6878 - Prevent repeated disconnect logs during shutdown #6879
- Issue 6859 - str2filter is not fully applying matching rules
- Issue 6756 - CLI, UI - Properly handle disabled NDN cache #6757
- Issue 6857 - uiduniq: allow specifying match rules in the filter
- Issue 6822 - Backend creation cleanup and Database UI tab error handling #6823
- Issue 6782 - Improve paged result locking
- Issue 6825 - RootDN Access Control Plugin with wildcards for IP addre… #6826
- Issue 6819 - Incorrect pwdpolicysubentry returned for an entry with user password policy
- Issue 6553 - Update concread to 0.5.6 #6824
- Issue 1081 - Add a CI test #6063
- Issue 6761 - Password modify extended operation should skip password policy checks when executed by root DN
- Issue 6470 (Cont) - Some replication status data are reset upon a restart
- Issue 6764 - statistics about index lookup report a wrong duration #6765
- Issue 5710 - subtree search statistics for index lookup does not report ancestorid/entryrdn lookups #5711
- Issue 3729 - (cont) RFE Extend log of operations statistics in access log #5538
- Issue 3729 - RFE Extend log of operations statistics in access log #5508
- Issue 6470 - Some replication status data are reset upon a restart #6471
- Issue 6641 - modrdn fails when a user is member of multiple groups #6643
- Issue 6787 - Improve error message when bulk import connection is closed
- Issue 6655 - fix merge conflict
- Issue 4989 - Confusing error message from dsconf plugin set –enabled #6750
- Issue 6734 - BUG - format strings may not contain backslash #6749
- Issue 6505- CI - backport changes for check_value_in_log
- Issue 6501 - CLI - dsidm role rename was not working
- Issue 6492/6493 - CLI - dsdim can not create nested/filtered roles
- Issue 6603 - Release tarballs ship a different Cargo.lock
- Issue 6743 - CLI - dsidm add option to list DN’s
- Issue 6735 - CLI - dsidm provide option to set decription when creating an entry
- Bump tokio from 1.43.0 to 1.44.2 in /src #6732
- Issue 6728 - CLI - Issue with user rename operation #6729
- Bump openssl from 0.10.70 to 0.10.72 in /src #6730
- Issue 6515 - CLI - dsidm get_dn does not return JSON format
- Issue 6494 - (4th) Various errors when using extended matching rule on vlv sort filter
- Issue 6494 - (3rd) Various errors when using extended matching rule on vlv sort filter
- Issue 6494 - (2nd) Various errors when using extended matching rule on vlv sort filter
- Issue 1925 - Add a CI test #5936
- Issue 6562 - Fix issues around slapi_filter_sprintf #6725
- Issue 6571 - (2nd) Nested group does not receive memberOf attribute #6697
- Issue 6686 - CLI - Re-enabling user accounts that reached inactivity limit fails with error #6687
- Issue 6288 - dsidm crash with account policy when alt-state-attr is disabled #6292
- Issue 6698 - NPE after configuring invalid filtered role #6699
- Issue 6571 - Nested group does not receive memberOf attribute #6679
- Issue 6676 - Add GitHub workflow action and fix pbkdf2 tests #6677
- Issue 6668 - Fix build break on 1.4.3 branch #6670
- Issue 6155 - ldap-agent fails to start because of permission error #6179
- Issue 6656 - UI - Enhance Monitor Log Viewer with Patternfly LogViewer component #6657
- Issue 6655 - fix replication release replica decoding error
- Issue 6632 - Replication init fails with ASAN build
- Issue 6436 - MOD on a large group slow if substring index is present #6437
- Issue 6553 - Update concread to 0.5.4 and refactor statistics tracking #6607
- Issue 4673 - Update Rust crates
- Bump esbuild from 0.24.0 to 0.25.0 in /src/cockpit/389-console #6602
- Issue 6561 - TLS 1.2 stickiness in FIPS mode
- Issue 5841 - dsconf incorrectly setting up Pass-Through Authentication #6601
- Bump openssl from 0.10.66 to 0.10.70 in /src
- Issue 6004 - (2nd) idletimeout may be ignored #6569
- Issue 6375 - UI - Update cockpit.js code to the latest version #6376
- Issue 5732 - Localizing Cockpit’s 389ds Plugin using CockpitPoPlugin #5764
- Issue 5793 - UI - movce from webpack to esbuild bundler
- Issue 5738 - RFE - UI - Read/write replication monitor info to .dsrc file
- Issue 6566 - RI plugin failure to handle a modrdn for rename of member of multiple groups #6567
- Issue 6004 - idletimeout may be ignored #6005
- Issue 6509 - Fix cherry pick issue (race condition in Paged results)
- Issue 6509 - Race condition with Paged Result searches
- Issue 6191 - Node.js 16 actions are deprecated
- Issue 6016 - Pin upload/download artifacts action to v3
- Issue 6497 - lib389 - Configure replication for multiple suffixes #6498
- Issue 6490 - Add a new macro function and print rounds on startup #6496
- Issue 6494 - Various errors when using extended matching rule on vlv sort filter #6495
- Issue 6417 - (3rd) If an entry RDN is identical to the suffix, then Entryrdn gets broken during a reindex #6480
- Issue 6490 - Remove the rust error log message for pbkdf2 rounds
- Issue 6485 - Fix double free in USN cleanup task
- Issue 6269 - RFE - Add nsslapd-pwdPBKDF2Rounds configuration to PBKDF2-* plugins #6447
- Issue 6417 - (2nd) fix typo
- Issue 6417 - (2nd) If an entry RDN is identical to the suffix, then Entryrdn gets broken during a reindex #6460
- Issue 6224 - Remove test_referral_subsuffix from ds_logs_test.py #6456
- Issue 3555 - UI - Fix issues reported by npm audit
- Issue 6302 - Allow to run replication status without a prompt #6410
- Issue 6417 - If an entry RDN is identical to the suffix, then Entryrdn gets broken during a reindex #6418
- Issue 6224 - Fix merge issue in 389-ds-base-2.1 for ds_log_test.py #6414
- Issue 6224 - d2entry - Could not open id2entry err 0 - at startup when having sub-suffixes #6225
- Issue 5920 - pamModuleIsThreadSafe is missing in the schema
- Issue 6067 - Update dsidm to prioritize basedn from .dsrc over interactive input #6362
- Issue 6331 - UI - Instance fails to load when DB backup directory doesn’t exist #6332
- Issue 6345 - Ensure all slapi_log_err calls end format strings with newline character \n #6346
- Security fix for CVE-2024-8445
- Issue 6336 - Fix failing CI tests (roles) due to slow import #6337
- Issue 6304 - RFE when memberof is enabled, defer updates of members from the update of the group
- Issue 6324 - Provide more information in the error message during setup_ol_tls_conn() #6325
- Issue 2472 - Add a CI test #6314
- Issue 6276 - Schema lib389 object is not keeping custom schema data upon editing #6279
- Issue 3555 - UI - Fix audit issue with npm - micromatch #6310
- Issue 6301 - Fix long delay when setting replication agreement with dsconf #6303
- Issue 6280 - Changelog trims updates from a given RID even if a consumer has not received any of them #6281
- Issue 6295 - test_password_modify_non_utf8 should set default password storage scheme
- Issue 6192 - Test failure: test_match_large_valueset
- Issue 2324 - Add a CI test #6289
Last modified on 10 September 2026