389 Directory Server 2.6.3
The 389 Directory Server team is proud to announce 389-ds-base version 2.6.3.
The new package and version is:
Source tarball: GitHub Releases
Highlights in 2.6.3
- Security fixes for CVE-2025-14905, CVE-2026-11770, CVE-2026-18355, CVE-2026-18453, CVE-2026-18922, CVE-2026-19843, CVE-2026-76560, CVE-2026-9064.
- Fix deferred MemberOf updates, replication-agreement validation, LMDB index updates, and replication total initialization.
- Prevent crashes and data loss during online reindex, large subtree rename, and retro changelog processing.
- Improve replication log analysis, WebUI group management, password policy controls, and index-repair tooling.
See Download for package installation and Install Guide for setup.
Changelog between 389-ds-base-2.6.2 and 389-ds-base-2.6.3:
- Bump version to 2.6.3
- Security fix for CVE-2026-76560
- Security fix for CVE-2026-19843
- Issue 7041 - Add WebUI test for group member management #7111
- Security fix for CVE-2026-18922
- Security fix for CVE-2026-18453
- Security fix for CVE-2026-18355
- Issue 7595 - Remove the nightly dedup gate and fix dispatched test runs
- Fix expiration time check #7718
- Issue 7774 - Add backport action #7775
- Issue 7770 - Testimony failure in test_cleanruv_extop_security.py #7771
- CVE-2026-11770 - Fix StartReplicationRequest auth gate response format
- Security fix for CVE-2026-11770
- Issue 3082 - Add test389.topologies compatibility shim for backports #7725
- Issue 7595 - Skip redundant CI runs to relieve the Actions queue #7753
- Issue 7760 - CI - harden dsconf_task_test.py
- Issue 4701 - Fix UAF when excluding attrs from retro changelog #7730
- Issue 7723 - Range search returns an empty result when its start key is removed #7724
- Issue 7735 - Heap overflow when parsing objectclass superior #7736
- Issue 7733 - Typo about nsuniqueid in tombstone_to_conflict #7734
- Issue 7707 - lib389: set nsDS5ReplicaBindDNGroup before ensure_agreement() in join_supplier/hub/consumer #7708
- Issue 7711 - Fix typo in accountpolicy –login-history-size help text #7713
- Issue 7688 - BUG - partial address leak in sso token #7689
- Issue 7705 - With memberOfEntryScope set, deferred memberOf skips MODIFY operations #7706
- Issue 7645 - Add runtime LeakSanitizer leak check #7646
- Issue 7714 - UI - sass import rules are deprecated
- Issue 7658 - Heap Buffer Overflow in sasl_io_recv() via Padded SASL UNBIND
- Issue 7710 - MemberOf deferred update - Use condvar instead of sleep loop
- Issue 7637 - fix cherry-pick error
- Issue 7637 - UI - Using Arrow Keys in New Object Wizard Resulted in DOM Reload
- Issue 7578 - schema - attribute refcount is not maintained properly
- Issue 7605 - Harden CI test ports against ephemeral allocation #7692
- Issue 7528 - Retry the CI image pull instead of failing the job #7691
- Issue 7460 - MOD_REPLACE on groups/link attributes modifies overlap targets #7461
- Issue 7670 - BDB range searches intermittently fail with err=1 under write load #7671
- Issue 7108 - Fix shutdown crash in entry cache destruction #7163
- Issue 7284 - Creating local password policy succeeds with incorrect passwordInHistory value #7662
- Issue 7284 - Automated test for creating local password policy with incorrect passwordInHistory value #7608
- Issue 7200 - repl-agmt create doesn’t set some parameters #7663
- Issue 7519 - Ignore obsolete entrydn index when entryrdn is enabled #7526
- Issue 7611 - Preserve legacy PBKDF2 hash compatibility #7649
- Issue 7547 - Heap buffer overflow in ldap_utf8prev()
- Issue 7611 - PBKDF2 password verification should reject invalid iteration count #7613
- Issue 7558 - Total init sends the suffix entry twice #7640
- Issue 7635 - Integer Underflow in {SMD5} Password Comparison #7636
- Issue 7406 - Fix ldap-agent SNMP stats file loading #7630
- Issue 7621 - Stack Buffer Overflow in Password checkPrefix
- Issue 7623 - Heap Buffer Overflow in 389-ds-base Audit Log Password Masking
- Issue 7602 - CI - lib389 user compare fails due to parentid mismatch #7603
- Issue 7537 - CI - Fix replication log monitoring parser/timing failures #7592
- Issue 7593 - Fix testimony docstring for SASL overflow test #7606
- Issue 7530 - CI - Stabilize DNA plugin replication tests timing out in CI #7572
- Issue 7593 - Reject invalid SASL packet length values in sasl_io_start_packet #7594
- Issue 3555 - UI - Fix audit issue with npm - ws, js-yaml, js-yaml, postcss, uuid
- Issue 7541 - Add invalid ACL text header regression test #7591
- Issue 7541 - heap-buffer-overflows in __aclp__normalize_acltxt() #7542
- Issue 7576 - Fix leak of temporary attribute syntax hash tables after schema reload
- Issue 7558 - During online import, the IDL should be created with in-depth first approach #7559
- Issue 7500 - Prevent unsigned integer underflow during stalled import
- Issue 7560 - lib389 - Add helper function for checking ASAN files
- Issue 7539 - Server shutdown during online reindex may lead to data loss #7540
- Issue 7549 - Substring index should validate minimum nsSubStrBegin/nsSubStrEnd values #7550
- Issue 7440 - Substring index produces empty results and can crash when non-default nsSubStrBegin/nsSubStrEnd lengths are configured #7441
- Fix test389 imports on older branches
- Issue 7267 - MDB_BAD_VALSIZE error when updating index #7268
- Issue 7437 - LeakSanitizer: memory leaks in CoS cache error paths #7438
- Issue 6922 - AddressSanitizer: leaks found by acl test suite
- Issue 3555 - UI - Fix audit issue with npm - brace-expansion #7556
- Issue 7554 - deref plugin null pointer dereference if ber_init fails
- Issue 7514 - Crash when doing moddn on very large subtree
- Issue 7516 - dblayer_bulk_nextdata should not return an error when maxrecords is hit
- Issue 7503 - CVE-2026-9064 - Add a limit to the number controls per operation
- Issue 7464 - CLI - allow dsidm to work with other user types
- Issue 7457 - Refactor memberOf perf test #7458
- Issue 7452 - UI - password polices - reorganize settings
- Issue 7431 - password policy - passwordBadWords is ignored in local policies
- Issue 7155 - build_candidate_list - Database error 11 with range search #7156
- Issue 7417 - UI - global password policy syntax settings missing passwordMaxRepeats
- Issue 3555 - UI - Fix audit issue with npm - brace-expansion #7411
- Issue 7088 - Change log level for “Can’t locate CSN” error message
- Issue 7423 - cleanup pblock after freeing pre/post entries
- Issue 7418 - Use-after-free in deferred memberof #7419
- Issue 7407 - dbscan -k option display entries that do not match the specified key
- Issue 7394 - UI - Manual typing of ports can leave out digits #7395
- Issue 7277 - UI - Fix Japanese translation errors errors in Cockpit UI #7386
- Issue 7126 - WARN - keys2idl - received NULL idl from index_read_ext_allids #7127
- Issue 7370 - Runtime LSan/TSan injection for pytest #7371
- Issue 7378 - Make sure suffix entry always gets assigned ID 1
- Issue 7380 - Internal op with negative wtime and large optime #7381
- Issue 7362 - UI - Some FormSelect onChange parameters are reversed
- Issue 7368 - UI - global password policy page is missing passwordmintokenlength
- Issue 7366 - Memory leaks in syncrepl plugin during persistent search operations #7367
- Issue 7284 - CI - Fix test_grace_limit_section after pwpolicy validation fix #7357
- Issue 7271 - Add test for retrocl trimming shutdown crash #7356
- Issue 3555 - UI - Fix audit issue with npm - flatted, picomatch #7364
- Issue 7322 - UI - add missing error handling function
- Issue 1704 - DNA plugin creates invalid shared config entry with port 0 #7352
- Issue 6753 - Removing ticket 477828 test and porting to DSLdapObject #6989
- Issue 7346 - DS does not handle escape char in bind user #7347
- Issue 7322 - Fix cherry-pick error (reject repl agmt that points to itself)
- Issue 7322 - Reject adding a replication agreement that points to itself
- Issue 7342 - CI - repl config regression #7343
- Issue 7319 - Action menu for certificates remains in empty certificate list #7320
- Issue 7265 - CI - fix retro changelog maxage validation test
- Issue 7093 - A password policy can be created even when an identical policy already exists #7283
- Issue 7233 - test_produce_division_by_zero fails with IsADirectoryError in conftest.py #7234
- Issue 7271 - Add new plugin pre-close function check to plugin_invoke_plugin_pb
- Issue 7304 - retrocl should not cache DN
- Issue 7265 - Add dse modify callback to validate retrocl trimming settings
- Issue 7152 - ns-slapd fails to shutdown when deferred memberof update is in progress #7187
- Issue 3555 - UI - Fix audit issue with npm - ajv, minimatch #7298
- Issue 7271 - implement a pre-close plugin function
- Issue 7291 - Crash when configuring a replica with an incorrect nsds5ReplicaRoot #7292
- Issue 7295 - changelog max age validation cherry-pick error
- Issue 7265 - changelog maxage validation is not strict enough
- Issue 7284 - Creating local password policy succeeds with incorrect passwordInHistory value #7285
- Security fix for CVE-2025-14905
- Issue 7277 - UI - Fix Japanese translation for “Successfully updated group” in Cockpit UI #7278
- Issue 7275 - UI - Improve password policy field validation in Cockpit UI #7276
- Issue 7279 - UI - Fix typo in export certificate dialog #7280
- Issue 7273 - In a chaining environment binding as remote user causes an invalid error in the logs
- Issue 7271 - plugins that create threads need to update
- Issue 5853 - Update concread to 0.5.10
- Issue 7053 - Remove memberof_del_dn_from_groups from MemberOf plugin #7064
- Issue 7223 - Remove integerOrderingMatch requirement for parentid #7264
- Issue 7243 - UI - fix certificate table and modal
- Issue 7066/7052 - allow password history to be set to zero and remove history
- Issue 7223 - Use lexicographical order for ancestorid #7256
- Issue 7213 - (2nd) MDB_BAD_VALSIZE error while handling VLV #7258
- Issue - CLI - dsctl db2index needs some hardening with MBD
- Issue 7248 - CLI - attribute uniqueness - fix usage for exclude subtree option
- Issue 7231 - Sync repl tests fail in FIPS mode due to non FIPS compliant crypto #7232
- Issue 7121 - (2nd) LeakSanitizer: various leaks during replication #7212
- Issue 6947 - Fix health_system_indexes_test.py
- Issue 7096 - (2nd) During replication online total init the function idl_id_is_in_idlist is not scaling with large database #7205
- Issue 3555 - UI - Fix audit issue with npm - @isaacs/brace-expansion #7228
- Issue 7223 - Add dsctl index-check command for offline index repair
- Issue 7223 - Detect and log index ordering mismatch during backend startup
- Issue 7223 - Add upgrade function to remove ancestorid index config entry
- Issue 7223 - Add upgrade function to remove nsIndexIDListScanLimit from parentid
- Issue 7223 - Revert index scan limits for system indexes
- Issue 7128 - memory corruption in alias entry plugin
- Issue 6476 - Fix build failure with GCC 15
- Issue 6542 - RPM build errors on Fedora 42
- Issue 7224 - CI Test - Simplify test_reserve_descriptor_validation #7225
- Issue 7194 - Repl Log Analysis - Add CSN propagation details #7195
- Issue 7213 - MDB_BAD_VALSIZE error while handling VLV #7214
- Issue 7027 - (2nd) 389-ds-base OpenScanHub Leaks Detected #7211
- Issue 7198 - Web console doesn’t show sub-suffix when parent-suffix points to an entry #7202
- Issue 7189 - DSBLE0007 generates incorrect remediation commands for scan limits
- Bump lodash from 4.17.21 to 4.17.23 in /src/cockpit/389-console #7203
- Issue 7172 - (2nd) Index ordering mismatch after upgrade #7180
- Issue 7172 - Index ordering mismatch after upgrade #7173
- Issue - Revise paged result search locking
- Issue 7096 - During replication online total init the function idl_id_is_in_idlist is not scaling with large database #7145
- Revert “Issue 7160 - Add lib389 version sync check to configure #7165”
- Issue 7160 - Add lib389 version sync check to configure #7165
- Issue 7012 - improve dscrl dbverify result when backend does not exists #7013 #7164
- Issue 7049 - RetroCL plugin generates invalid LDIF
- Issue 7150 - Compressed access log rotations skipped, accesslog-list out of sync #7151
- Issue 7119 - Fix DNA shared config replication test #7143
- Issue 7081 - Repl Log Analysis - Implement data sampling with performance and timezone fixes #7086
- Issue 7128 - memory corruption in alias entry plugin #7131
- Issue 7091 - Duplicate local password policy entries listed #7092
- Issue 7124 - BDB cursor race condition with transaction isolation #7125
- Issue 7132 - Keep alive entry updated too soon after an offline import #7133
- Issue 7121 - LeakSanitizer: various leaks during replication #7122
- Issue 7115 - LeakSanitizer: leak in
slapd\_bind\_local\_user() #7116
- Issue 7109 - AddressSanitizer: SEGV ldap/servers/slapd/csnset.c:302 in csnset_dup #7114
- Issue 7056 - DSBLE0007 doesn’t generate remediation steps for missing indexes
- Issue 7119 - Harden DNA plugin locking for shared server list operations #7120
- Issue 7084 - UI - schema - sorting attributes breaks expanded row
- Issue 7007 - Improve paged result search locking
- Issue 3555 - UI - Fix audit issue with npm - glob #7107
- Issue 6846 - Attribute uniqueness is not enforced with modrdn #7026
- Issue 6901 - Update changelog trimming logging - fix tests
- Issue 6901 - Update changelog trimming logging
- Bump js-yaml from 4.1.0 to 4.1.1 in /src/cockpit/389-console #7097
- Issue 7069 - Fix error reporting in HAProxy trusted IP parsing #7094
- Issue 7042 - Enable global_backend_lock when memberofallbackend is enabled #7043
- Issue 7055 - Online initialization of consumers fails with error -23 #7075
- Issue 7078 - audit json logging does not encode binary values
- Issue 7069 - Add Subnet/CIDR Support for HAProxy Trusted IPs #7070
- Issue 6660 - CLI, UI - Improve replication log analyzer usability #7062
- Issue 7065 - A search filter containing a non normalized DN assertion does not return matching entries #7068
- Issue 7071 - search filter (&(cn:dn:=groups)) no longer returns results
- Issue 7073 - Add NDN cache size configuration and enforcement tests #7074
- Issue 7041 - CLI/UI - memberOf - no way to add/remove specific group filters
- Issue 7061 - CLI/UI - Improve error messages for dsconf localpwp list
- Issue 7059 - UI - unable to upload pem file
- Issue 7032 - The new ipahealthcheck test ipahealthcheck.ds.backends.BackendsCheck raises CRITICAL issue #7036
- Issue 7047 - MemberOf plugin logs null attribute name on fixup task completion #7048
- Issue 7044 - RFE - index sudoHost by default #7046
- Issue 6979 - Improve the way to detect asynchronous operations in the access logs #6980
- Issue 7035 - RFE - memberOf - adding scoping for specific groups
- Issue - CLI/UI - Add option to delete all replication conflict entries
- Issue 7033 - lib389 - basic plugin status not in JSON
- Issue 7023 - UI - if first instance that is loaded is stopped it breaks parts of the UI
- Issue 7027 - 389-ds-base OpenScanHub Leaks Detected #7028
- Issue 6966 - On large DB, unlimited IDL scan limit reduce the SRCH performance #6967
- Issue 6660 - UI - Improve replication log analysis charts and usability #6968
- Issue 6982 - UI - MemberOf shared config does not validate DN properly #6983
- Issue 7021 - Units for changing MDB max size are not consistent across different tools #7022
- Issue 6954 - do not delete referrals on chain_on_update backend
- Issue 7018 - BUG - prevent stack depth being hit #7019
- Issue 6928 - The parentId attribute is indexed with improper matching rule
- Issue 6933 - When deferred memberof update is enabled after the server crashed it should not launch memberof fixup task by default #6935
- Issue 7014 - memberOf - ignored deferred updates with LMDB
- Issue 6929 - Compilation failure with rust-1.89 on Fedora ELN
- Issue 6990 - UI - Replace deprecated Select components with new TypeaheadSelect #6996
- Issue 6990 - UI - Fix typeahead Select fields losing values on Enter keypress #6991
- Issue 6977 - UI - Show error message when trying to use unavailable ports #6978
- Issue 6956 - More UI fixes
- Issue 6947 - Revise time skew check in healthcheck tool and add option
- Issue - UI - update Radio handlers and LDAP entries last modified time
- Issue 6660 - UI - Fix minor typo #6955
- Issue 6910 - Fix latest coverity issues
- Issue 6919 - numSubordinates/tombstoneNumSubordinates are inconsisten… #6920
- Issue 6940 - dsconf monitor server fails with ldapi:// due to absent server ID #6941
- Issue 6936 - Make user/subtree policy creation idempotent #6937
- Issue 6865 - AddressSanitizer: leak in agmt_update_init_status
- Issue 6848 - AddressSanitizer: leak in do_search
- Issue 6850 - AddressSanitizer: memory leak in mdb_init
- Issue 6778 - Memory leak in roles_cache_create_object_from_entry part 2
- Issue 6778 - Memory leak in roles_cache_create_object_from_entry
- Issue 6181 - RFE - Allow system to manage uid/gid at startup
- Issues 6913, 6886, 6250 - Adjust xfail marks #6914
- Issue 6768 - ns-slapd crashes when a referral is added #6780
- Issue 6468 - CLI - Fix default error log level
- Issue 6339 - Address Coverity scan issues in memberof and bdb_layer #6353
- Issue 6897 - Fix disk monitoring test failures and improve test maintainability #6898
- Issue 6884 - Mask password hashes in audit logs #6885
- Issue 6594 - Add test for numSubordinates replication consistency with tombstones #6862
- Issue 6250 - Add test for entryUSN overflow on failed add operations #6821
- Issue 6895 - Crash if repl keep alive entry can not be created
- Issue 6893 - Log user that is updated during password modify extended operation
- Issue 6772 - dsconf - Replicas with the “consumer” role allow for viewing and modification of their changelog. #6773
- Issue 6680 - instance read-only mode is broken #6681
- Issue 6878 - Prevent repeated disconnect logs during shutdown #6879
- Issue 6872 - compressed log rotation creates files with world readable permission
- Issue 6859 - str2filter is not fully applying matching rules
- Issue 6868 - UI - schema attribute table expansion break after moving to
- Issue 6756 - CLI, UI - Properly handle disabled NDN cache #6757
- Issue 6857 - uiduniq: allow specifying match rules in the filter
- Issue 6838 - lib389/replica.py is using nonexistent datetime.UTC in Python 3.9
- Issue 6377 - syntax error in setup.py #6378
- Issue 6822 - Backend creation cleanup and Database UI tab error handling #6823
- Issue 6782 - Improve paged result locking
- Issue 6119 - Synchronise accept_thread with slapd_daemon #6120
- Issue 6825 - RootDN Access Control Plugin with wildcards for IP addre… #6826
Last modified on 10 September 2026