389 Directory Server 2.2.11
The 389 Directory Server team is proud to announce 389-ds-base version 2.2.11.
The new package and version is:
Source tarball: GitHub Releases
Highlights in 2.2.11
- Security fixes for CVE-2025-14905, CVE-2026-11770, CVE-2026-18355, CVE-2026-18453, CVE-2026-18922, CVE-2026-19843, CVE-2026-76560, CVE-2026-9064.
- Fix expiration-time validation, PBKDF2 compatibility and validation, and local password policy handling.
- Prevent crashes and data loss during online reindex, large subtree rename, and retro changelog processing.
- Improve range searches, replication setup and initialization, and index-repair tooling.
See Download for package installation and Install Guide for setup.
Changelog between 389-ds-base-2.2.10 and 389-ds-base-2.2.11:
- Bump version to 2.2.11
- Security fix for CVE-2026-76560
- Security fix for CVE-2026-19843
- Security fix for CVE-2026-18922
- Security fix for CVE-2026-18453
- Security fix for CVE-2026-18355
- Issue 7595 - Remove the nightly dedup gate and fix dispatched test runs
- Fix expiration time check #7718
- Issue 7774 - Add backport action #7775
- Issue 7770 - Testimony failure in test_cleanruv_extop_security.py #7771
- Issue 1704 - Include stdbool.h in slapi headers on 2.4 #7768
- CVE-2026-11770 - Fix StartReplicationRequest auth gate response format
- Security fix for CVE-2026-11770
- Issue 3082 - Add test389.topologies compatibility shim for backports #7725
- Issue 7595 - Skip redundant CI runs to relieve the Actions queue #7755
- Issue 4701 - Fix UAF when excluding attrs from retro changelog #7730
- Issue 7723 - Range search returns an empty result when its start key is removed #7724
- Issue 7735 - Heap overflow when parsing objectclass superior #7736
- Issue 7733 - Typo about nsuniqueid in tombstone_to_conflict #7734
- Issue 7707 - lib389: set nsDS5ReplicaBindDNGroup before ensure_agreement() in join_supplier/hub/consumer #7708
- Issue 7688 - BUG - partial address leak in sso token #7689
- Issue 7711 - Fix typo in accountpolicy –login-history-size help text #7713
- Issue 7645 - Add runtime LeakSanitizer leak check #7646
- Issue 7658 - Heap Buffer Overflow in sasl_io_recv() via Padded SASL UNBIND
- Issue 7605 - Harden CI test ports against ephemeral allocation #7692
- Issue 7528 - Retry the CI image pull instead of failing the job #7691
- Issue 7460 - MOD_REPLACE on groups/link attributes modifies overlap targets #7461
- Issue 7670 - BDB range searches intermittently fail with err=1 under write load #7671
- Issue 7108 - Fix shutdown crash in entry cache destruction #7163
- Issue 7284 - Creating local password policy succeeds with incorrect passwordInHistory value #7662
- Issue 7284 - Automated test for creating local password policy with incorrect passwordInHistory value #7608
- Issue 7200 - repl-agmt create doesn’t set some parameters #7663
- Issue 7611 - Preserve legacy PBKDF2 hash compatibility #7649
- Issue 7547 - Heap buffer overflow in ldap_utf8prev()
- Issue 7611 - PBKDF2 password verification should reject invalid iteration count #7613
- Issue 7558 - Total init sends the suffix entry twice #7640
- Issue 7635 - Integer Underflow in {SMD5} Password Comparison #7636
- Issue 7406 - Fix ldap-agent SNMP stats file loading #7630
- Issue 7621 - Stack Buffer Overflow in Password checkPrefix
- Issue 7623 - Heap Buffer Overflow in 389-ds-base Audit Log Password Masking
- Issue 6625 - Backport get_pid to fix check_asan_report #7625
- Issue 7602 - CI - lib389 user compare fails due to parentid mismatch #7603
- Issue 7537 - CI - Fix replication log monitoring parser/timing failures #7592
- Issue 7593 - Fix testimony docstring for SASL overflow test #7606
- Issue 7530 - CI - Stabilize DNA plugin replication tests timing out in CI #7572
- Issue 7593 - Reject invalid SASL packet length values in sasl_io_start_packet #7594
- Issue 3555 - UI - Fix audit issue with npm - ws, js-yaml, js-yaml, postcss, uuid
- Issue 7541 - Add invalid ACL text header regression test #7591
- Issue 7541 - heap-buffer-overflows in __aclp__normalize_acltxt() #7542
- Issue 7576 - Fix leak of temporary attribute syntax hash tables after schema reload
- Issue 7558 - During online import, the IDL should be created with in-depth first approach #7559
- Issue 7500 - Prevent unsigned integer underflow during stalled import
- Issue 7560 - lib389 - Add helper function for checking ASAN files
- Issue 7539 - Server shutdown during online reindex may lead to data loss #7540
- Issue 7549 - Substring index should validate minimum nsSubStrBegin/nsSubStrEnd values #7550
- Issue 7440 - Substring index produces empty results and can crash when non-default nsSubStrBegin/nsSubStrEnd lengths are configured #7441
- Fix test389 imports on older branches
- Issue 7437 - LeakSanitizer: memory leaks in CoS cache error paths #7438
- Issue 6922 - AddressSanitizer: leaks found by acl test suite
- Issue 3555 - UI - Fix audit issue with npm - brace-expansion #7556
- Issue 7554 - deref plugin null pointer dereference if ber_init fails
- Issue 7514 - Crash when doing moddn on very large subtree
- Issue 7516 - dblayer_bulk_nextdata should not return an error when maxrecords is hit
- Issue 7503 - CVE-2026-9064 - Add a limit to the number controls per operation
- Issue 7457 - Refactor memberOf perf test #7458
- Issue 7431 - password policy - passwordBadWords is ignored in local policies
- Issue 7417 - UI - global password policy syntax settings missing passwordMaxRepeats
- Issue 3555 - UI - Fix audit issue with npm - brace-expansion #7411
- Issue 7088 - Change log level for “Can’t locate CSN” error message
- Issue 7423 - cleanup pblock after freeing pre/post entries
- Issue 7418 - Use-after-free in deferred memberof #7419
- Issue 7277 - UI - Fix Japanese translation errors errors in Cockpit UI #7386
- Issue 7126 - WARN - keys2idl - received NULL idl from index_read_ext_allids #7127
- Issue 7370 - Runtime LSan/TSan injection for pytest #7371
- Issue 7378 - Make sure suffix entry always gets assigned ID 1
- Issue 7380 - Internal op with negative wtime and large optime #7381
- Issue 7362 - UI - Some FormSelect onChange parameters are reversed
- Issue 7368 - UI - global password policy page is missing passwordmintokenlength
- Issue 7366 - Memory leaks in syncrepl plugin during persistent search operations #7367
- Issue 7284 - CI - Fix test_grace_limit_section after pwpolicy validation fix #7357
- Issue 3555 - UI - Fix audit issue with npm - flatted, picomatch #7364
- Issue 1704 - DNA plugin creates invalid shared config entry with port 0 #7352
- Issue 6753 - Removing ticket 477828 test and porting to DSLdapObject #6989
- Issue 7342 - CI - repl config regression #7343
- Issue 7319 - Action menu for certificates remains in empty certificate list #7320
- Issue 6868 - UI - schema attribute table expansion break after moving to
- Issue 7093 - A password policy can be created even when an identical policy already exists #7283
- Issue 7233 - test_produce_division_by_zero fails with IsADirectoryError in conftest.py #7234
- Issue 7152 - ns-slapd fails to shutdown when deferred memberof update is in progress #7187
- Issue 3555 - UI - Fix audit issue with npm - ajv, minimatch #7298
- Issue 7291 - Crash when configuring a replica with an incorrect nsds5ReplicaRoot #7292
- Issue 7284 - Creating local password policy succeeds with incorrect passwordInHistory value #7285
- Security fix for CVE-2025-14905
- Issue 7277 - UI - Fix Japanese translation for “Successfully updated group” in Cockpit UI #7278
- Issue 7275 - UI - Improve password policy field validation in Cockpit UI #7276
- Issue 7279 - UI - Fix typo in export certificate dialog #7280
- Issue 5853 - Update concread to 0.5.10
- Issue 7223 - Remove integerOrderingMatch requirement for parentid #7264
- Issue 7223 - Use lexicographical order for ancestorid #7256
- Issue 7231 - Sync repl tests fail in FIPS mode due to non FIPS compliant crypto #7232
- Issue 7121 - (2nd) LeakSanitizer: various leaks during replication #7212
- Issue 3555 - UI - Fix audit issue with npm - @isaacs/brace-expansion #7228
- Issue 7223 - Add dsctl index-check command for offline index repair
- Issue 7223 - Detect and log index ordering mismatch during backend startup
- Issue 7223 - Add upgrade function to remove ancestorid index config entry
- Issue 7223 - Add upgrade function to remove nsIndexIDListScanLimit from parentid
- Issue 7223 - Revert index scan limits for system indexes
- Issue 6476 - Fix build failure with GCC 15
- Issue 6542 - RPM build errors on Fedora 42
- Issue 7224 - CI Test - Simplify test_reserve_descriptor_validation #7225
- Issue 7027 - (2nd) 389-ds-base OpenScanHub Leaks Detected #7211
- Issue 7198 - Web console doesn’t show sub-suffix when parent-suffix points to an entry #7202
- Issue 7189 - DSBLE0007 generates incorrect remediation commands for scan limits
- Bump lodash from 4.17.21 to 4.17.23 in /src/cockpit/389-console #7203
- Issue 7172 - (2nd) Index ordering mismatch after upgrade #7180
- Issue 7172 - Index ordering mismatch after upgrade #7173
- Issue - Revise paged result search locking
- Issue 7096 - During replication online total init the function idl_id_is_in_idlist is not scaling with large database #7145
- Issue 7119 - Fix DNA shared config replication test #7143
- Issue 7128 - memory corruption in alias entry plugin #7131
- Issue 7091 - Duplicate local password policy entries listed #7092
- Issue 7124 - BDB cursor race condition with transaction isolation #7125
- Issue 7121 - LeakSanitizer: various leaks during replication #7122
- Issue 7115 - LeakSanitizer: leak in
slapd\_bind\_local\_user() #7116
- Issue 7109 - AddressSanitizer: SEGV ldap/servers/slapd/csnset.c:302 in csnset_dup #7114
- Issue 7056 - DSBLE0007 doesn’t generate remediation steps for missing indexes
- Issue 7119 - Harden DNA plugin locking for shared server list operations #7120
- Issue 7007 - Improve paged result search locking
- Issue 3555 - UI - Fix audit issue with npm - glob #7107
- Issue 6846 - Attribute uniqueness is not enforced with modrdn #7026
- Bump js-yaml from 4.1.0 to 4.1.1 in /src/cockpit/389-console #7097
- Issue 7042 - Enable global_backend_lock when memberofallbackend is enabled #7043
- Issue 7055 - Online initialization of consumers fails with error -23 #7075
- Issue 7065 - A search filter containing a non normalized DN assertion does not return matching entries #7068
- Issue 7071 - search filter (&(cn:dn:=groups)) no longer returns results
- Issue 7073 - Add NDN cache size configuration and enforcement tests #7074
- Issue 7061 - CLI/UI - Improve error messages for dsconf localpwp list
- Issue 7059 - UI - unable to upload pem file
- Issue 7032 - The new ipahealthcheck test ipahealthcheck.ds.backends.BackendsCheck raises CRITICAL issue #7036
- Issue 7047 - MemberOf plugin logs null attribute name on fixup task completion #7048
- Issue 6979 - Improve the way to detect asynchronous operations in the access logs #6980
- Issue - CLI/UI - Add option to delete all replication conflict entries
- Issue 7033 - lib389 - basic plugin status not in JSON
- Issue 7023 - UI - if first instance that is loaded is stopped it breaks parts of the UI
- Issue 7027 - 389-ds-base OpenScanHub Leaks Detected #7028
- Issue 6966 - On large DB, unlimited IDL scan limit reduce the SRCH performance #6967
- Issue 6954 - do not delete referrals on chain_on_update backend
- Issue 7018 - BUG - prevent stack depth being hit #7019
- Issue 6928 - The parentId attribute is indexed with improper matching rule
- Issue 6933 - When deferred memberof update is enabled after the server crashed it should not launch memberof fixup task by default #6935
- Issue 6929 - Compilation failure with rust-1.89 on Fedora ELN
- Issue 6764 - statistics about index lookup report a wrong duration #6765
- Issue 6641 - Fix memory leaks
- Issue 6940 - dsconf monitor server fails with ldapi:// due to absent server ID #6941
- Issue 6936 - Make user/subtree policy creation idempotent #6937
- Issue 6865 - AddressSanitizer: leak in agmt_update_init_status
- Issue 6848 - AddressSanitizer: leak in do_search
- Issue 6850 - AddressSanitizer: memory leak in mdb_init
- Issue 6778 - Memory leak in roles_cache_create_object_from_entry part 2
- Issue 6778 - Memory leak in roles_cache_create_object_from_entry
- Issue 6181 - RFE - Allow system to manage uid/gid at startup
- Issues 6913, 6886, 6250 - Adjust xfail marks #6914
- Issue 6768 - ns-slapd crashes when a referral is added #6780
- Issue 6468 - CLI - Fix default error log level
- Issue 6897 - Fix disk monitoring test failures and improve test maintainability #6898
- Issue 6884 - Mask password hashes in audit logs #6885
- Issue 6594 - Add test for numSubordinates replication consistency with tombstones #6862
- Issue 6250 - Add test for entryUSN overflow on failed add operations #6821
- Issue 6895 - Crash if repl keep alive entry can not be created
- Issue 6893 - Log user that is updated during password modify extended operation
- Issue 6772 - dsconf - Replicas with the “consumer” role allow for viewing and modification of their changelog. #6773
- Issue 6680 - instance read-only mode is broken #6681
- Issue 6878 - Prevent repeated disconnect logs during shutdown #6879
- Issue 6872 - compressed log rotation creates files with world readable permission
- Issue 6859 - str2filter is not fully applying matching rules
- Issue 6756 - CLI, UI - Properly handle disabled NDN cache #6757
- Issue 6857 - uiduniq: allow specifying match rules in the filter
- Issue 6838 - lib389/replica.py is using nonexistent datetime.UTC in Python 3.9
- Issue 6822 - Backend creation cleanup and Database UI tab error handling #6823
- Issue 6782 - Improve paged result locking
- Issue 6119 - Synchronise accept_thread with slapd_daemon #6120
- Issue 6825 - RootDN Access Control Plugin with wildcards for IP addre… #6826
- Issue 6736 - Exception thrown by dsconf instance repl get_ruv #6742
- Issue 6819 - Incorrect pwdpolicysubentry returned for an entry with user password policy
- Issue 6553 - Update concread to 0.5.6 #6824
- Issue 1081 - Add a CI test #6063
- Issue 6761 - Password modify extended operation should skip password policy checks when executed by root DN
- Issue 6715 - dsconf backend replication monitor fails if replica id starts with 0 #6716
- Issue 6698 - NPE after configuring invalid filtered role #6699
- Issue 6641 - modrdn fails when a user is member of multiple groups #6643
- Issue 6776 - Enabling audit log makes slapd coredump
- Issue 6534 - CI fails with Fedora 41 and DNF5
- Issue 6787 - Improve error message when bulk import connection is closed
- Issue 6626 - Ignore replica busy condition in healthcheck #6630
- Revert “Issue 5120 - ns-slapd doesn’t start in referral mode #6763”
- Issue 6438 - Add basic dsidm organizational unit tests
- Issue 6439 - Fix dsidm service get_dn option
- Issue 5120 - ns-slapd doesn’t start in referral mode #6763
- Issue 4989 - Confusing error message from dsconf plugin set –enabled #6750
- Issue 6276 - UI - schema editing and memberof shared config not working correctly
- Issue 6734 - BUG - format strings may not contain backslash #6749
- Issue 6505- CI - backport changes for check_value_in_log
- Issue 6501 - CLI - dsidm role rename was not working
- Issue 6744 - BUG - memory accounting is not always enabled #6745
- Issue 6492/6493 - CLI - dsdim can not create nested/filtered roles
- Issue #6740 Certificate verify fails in FIPS mode
- Issue 5356 - Set DEFAULT_PASSWORD_STORAGE_SCHEME to PBKDF2-SHA512 in tests
- Issue 6603 - Release tarballs ship a different Cargo.lock
- Issue 6743 - CLI - dsidm add option to list DN’s
- Issue 6735 - CLI - dsidm provide option to set decription when creating an entry
- Bump tokio from 1.43.0 to 1.44.2 in /src #6732
- Issue 6728 - CLI - Issue with user rename operation #6729
- Bump openssl from 0.10.70 to 0.10.72 in /src #6730
- Issue 6515 - CLI - dsidm get_dn does not return JSON format
- Issue 6713 - ns-slapd crash during mdb offline import #6714
- Issue 6562 - Fix issues around slapi_filter_sprintf #6725
- Issue 6464 - UI - Fixed spelling in cockpit messages
- Issue 6571 - (2nd) Nested group does not receive memberOf attribute #6697
- Issue 6686 - CLI - Re-enabling user accounts that reached inactivity limit fails with error #6687
- Issue 6288 - dsidm crash with account policy when alt-state-attr is disabled #6292
- Issue 6494 - (4th) Various errors when using extended matching rule on vlv sort filter
- Issue 6494 - (3rd) Various errors when using extended matching rule on vlv sort filter
- Issue 1925 - Add a CI test #5936
- Issue 6571 - Nested group does not receive memberOf attribute #6679
- Issue 6676 - Add GitHub workflow action and fix pbkdf2 tests #6677
- Issue 6155 - ldap-agent fails to start because of permission error #6179
- Issue 6656 - UI - Enhance Monitor Log Viewer with Patternfly LogViewer component #6657
- Issue 6655 - fix replication release replica decoding error
- Issue 6632 - Replication init fails with ASAN build
- Issue 6436 - MOD on a large group slow if substring index is present #6437
- Issue 6553 - Update concread to 0.5.4 and refactor statistics tracking #6607
- Issue 4673 - Update Rust crates
- Bump esbuild from 0.24.0 to 0.25.0 in /src/cockpit/389-console #6602
- Issue 6561 - TLS 1.2 stickiness in FIPS mode
- Issue 6494 - (2nd) Various errors when using extended matching rule on vlv sort filter
- Issue 6343 - (2nd) Improve online import robustness when the server is under load
- Issue 6554 - During import of entries without nsUniqueId, a supplier generates duplicate nsUniqueId (LMDB only) #6582
- Bump openssl from 0.10.66 to 0.10.70 in /src
- Issue 6258 - Mitigate race condition in paged_results_test.py #6433
- Issue 6566 - RI plugin failure to handle a modrdn for rename of member of multiple groups #6567
- Issue 6375 - UI - Update cockpit.js code to the latest version #6376
- Issue 5732 - Localizing Cockpit’s 389ds Plugin using CockpitPoPlugin #5764
- Issue 5793 - UI - movce from webpack to esbuild bundler
- Issue 6004 - idletimeout may be ignored #6005
- Issue 6468 - Fix building for older versions of Python
- Issue 6446 - Fix test_acct_policy_consumer test to wait enough for lastLoginHistory update #6530
- Issue 6509 - Race condition with Paged Result searches
- Issue 6191 - Node.js 16 actions are deprecated
- Issue 6016 - Pin upload/download artifacts action to v3
- Issue 6497 - lib389 - Configure replication for multiple suffixes #6498
- Issue 6470 - Some replication status data are reset upon a restart #6471
- Issue 6386 - backup/restore broken after db log rotation #6406
- Issue 6490 - Add a new macro function and print rounds on startup #6496
- Issue 6494 - Various errors when using extended matching rule on vlv sort filter #6495
- Issue 6417 - (3rd) If an entry RDN is identical to the suffix, then Entryrdn gets broken during a reindex #6480
- Issue 6490 - Remove the rust error log message for pbkdf2 rounds
- Issue 6485 - Fix double free in USN cleanup task
- Issue 6269 - RFE - Add nsslapd-pwdPBKDF2Rounds configuration to PBKDF2-* plugins #6447
- Issue 6468 - RFE - CLI - fix cherry-pick error
- Issue 6468 - RFE - CLI - Add logging settings to dsconf
- Issue 6472 - CLI - Improve error message format
- Issue 6417 - (2nd) typo
- Issue 6417 - (2nd) If an entry RDN is identical to the suffix, then Entryrdn gets broken during a reindex #6460
- Issue 3555 - UI - Fix issues reported by npm audit
- Issue 6446 - on replica consumer, account policy plugin fails to manage the last login history #6448
- Issue 6432 - Crash during bind when acct policy plugin does not have “alwaysrecordlogin” set
- Issue 6302 - Allow to run replication status without a prompt #6410
- Issue 6417 - If an entry RDN is identical to the suffix, then Entryrdn gets broken during a reindex #6418
- Issue 6340 - RFE - extract keys once #6413
- Issue 6415 - BUG - Incorrect icu linking #6416
- Issue 6258 - Resolve race condition for two tests in health_config.py
- Issue 6086 - Ambiguous warning about SELinux in dscreate for non-root user
- Issue 6349 - RFE - extract keys once #6363 #6394
- Issue 5920 - pamModuleIsThreadSafe is missing in the schema
- Issue 6349 - RFE - Use previously extracted key path #6363
- Issue 6067 - Update dsidm to prioritize basedn from .dsrc over interactive input #6362
- Issue 6331 - UI - Instance fails to load when DB backup directory doesn’t exist #6332
- Issue 6343 - Improve online import robustness when the server is under load
- Issue 6345 - Ensure all slapi_log_err calls end format strings with newline character \n #6346
- Issue 6336 - Fix failing CI tests (roles) due to slow import #6337
- Issue 6304 - RFE when memberof is enabled, defer updates of members from the update of the group #6305
- Issue 6324 - Provide more information in the error message during setup_ol_tls_conn() #6325
- Issue 6307 - Wrong set of entries returned for some search filters #6308
- Issue 2472 - Add a CI test #6314
- Issue 6276 - Schema lib389 object is not keeping custom schema data upon editing #6279
- Issue 3555 - UI - Fix audit issue with npm - micromatch #6310
- Issue 6301 - Fix long delay when setting replication agreement with dsconf #6303
- Issue 6280 - Changelog trims updates from a given RID even if a consumer has not received any of them #6281
- Issue 6295 - test_password_modify_non_utf8 should set default password storage scheme
- Issue 6192 - Test failure: test_match_large_valueset
- Issue 2324 - Add a CI test #6289
- Issue 6284 - BUG - freelist ordering causes high wtime
Last modified on 10 September 2026