389 Directory Server 2.9.1
The 389 Directory Server team is proud to announce 389-ds-base version 2.9.1.
The new package and version is:
Source tarball: GitHub Releases
Highlights in 2.9.1
See Download for package installation and Install Guide for setup.
Changelog between 389-ds-base-2.9.0 and 389-ds-base-2.9.1:
- Bump version to 2.9.1
- Security fix for CVE-2026-76560
- Security fix for CVE-2026-19843
- Issue 7041 - Add WebUI test for group member management #7111
- Security fix for CVE-2026-18922
- Security fix for CVE-2026-18453
- Security fix for CVE-2026-18355
- Issue 7808 - CI - harden online_import_nosync_test #7809
- Issue 7595 - Remove the nightly dedup gate and fix dispatched test runs
- Fix expiration time check #7718
- Issue 7774 - Add backport action #7775
- Issue 7770 - Testimony failure in test_cleanruv_extop_security.py #7771
- CVE-2026-11770 - Fix StartReplicationRequest auth gate response format
- Security fix for CVE-2026-11770
- Issue 3082 - Add test389.topologies compatibility shim for backports #7725
- Issue 7595 - Skip redundant CI runs to relieve the Actions queue #7750
- Issue 7760 - CI - harden dsconf_task_test.py
- Issue 7723 - Range search returns an empty result when its start key is removed #7724
- Issue 7735 - Heap overflow when parsing objectclass superior #7736
- Issue 7733 - Typo about nsuniqueid in tombstone_to_conflict #7734
- Issue 7284 - Creating local password policy succeeds with incorrect passwordInHistory value #7662
- Issue 7284 - Automated test for creating local password policy with incorrect passwordInHistory value #7608
- Issue 7284 - CI - Fix test_grace_limit_section after pwpolicy validation fix #7357
- Issue 7284 - Creating local password policy succeeds with incorrect passwordInHistory value #7285
- Issue 7707 - lib389: set nsDS5ReplicaBindDNGroup before ensure_agreement() in join_supplier/hub/consumer #7708
- Issue 7688 - BUG - partial address leak in sso token #7689
- Issue 7711 - Fix typo in accountpolicy –login-history-size help text #7713
- Issue 7705 - With memberOfEntryScope set, deferred memberOf skips MODIFY operations #7706
- Issue 7698 - Fix silent entry loss in LMDB bulk import waiter handling #7699
- Issue 7666 - Replication performance degradation during total init on high-latency storage #7667
- Issue 7201 - Syscall overhead in LMDB import writer thread #7204
- Issue 7645 - Add runtime LeakSanitizer leak check #7646
- Issue 7714 - UI - sass import rules are deprecated
- Issue 7658 - Heap Buffer Overflow in sasl_io_recv() via Padded SASL UNBIND
- Issue 7710 - MemberOf deferred update - Use condvar instead of sleep loop
- Issue 7637 - fix cherry-pick error
- Issue 7637 - UI - Using Arrow Keys in New Object Wizard Resulted in DOM Reload
- Issue 7578 - schema - attribute refcount is not maintained properly
- Issue 7605 - Harden CI test ports against ephemeral allocation #7692
- Issue 7528 - Retry the CI image pull instead of failing the job #7691
- Issue 7460 - MOD_REPLACE on groups/link attributes modifies overlap targets #7461
- Issue 7670 - BDB range searches intermittently fail with err=1 under write load #7671
- Issue 7108 - Fix shutdown crash in entry cache destruction #7163
- Issue 7200 - repl-agmt create doesn’t set some parameters #7663
- Issue 7593 - Fix testimony docstring for SASL overflow test #7606
- Issue 7593 - Reject invalid SASL packet length values in sasl_io_start_packet #7594
- Issue 7611 - Preserve legacy PBKDF2 hash compatibility #7649
- Issue 7611 - PBKDF2 password verification should reject invalid iteration count #7613
- Issue 7547 - Heap buffer overflow in ldap_utf8prev()
- Issue 7558 - Total init sends the suffix entry twice #7640
- Issue 7406 - Fix ldap-agent SNMP stats file loading #7630
- Issue 7621 - Stack Buffer Overflow in Password checkPrefix
- Issue 7623 - Heap Buffer Overflow in 389-ds-base Audit Log Password Masking
- Issue 6753 - Port ticket 47963 & 49184 tests #6970
- Issue 7602 - CI - lib389 user compare fails due to parentid mismatch #7603
- Issue 3555 - UI - Fix audit issue with npm - ws, js-yaml, js-yaml, postcss, uuid
- Issue 7541 - Add invalid ACL text header regression test #7591
- Issue 7541 - heap-buffer-overflows in __aclp__normalize_acltxt() #7542
- Issue 7576 - Fix leak of temporary attribute syntax hash tables after schema reload
- Issue 7198 - Web console doesn’t show sub-suffix when parent-suffix points to an entry #7202
- Issue 7558 - During online import, the IDL should be created with in-depth first approach #7559
- Issue 7500 - Prevent unsigned integer underflow during stalled import
- Issue 7560 - lib389 - Add helper function for checking ASAN files
- Issue 7539 - Server shutdown during online reindex may lead to data loss #7540
- Issue 7549 - Substring index should validate minimum nsSubStrBegin/nsSubStrEnd values #7550
- Issue 7440 - Substring index produces empty results and can crash when non-default nsSubStrBegin/nsSubStrEnd lengths are configured #7441
- Fix test389 imports on older branches
- Issue 7267 - MDB_BAD_VALSIZE error when updating index #7268
- Issue 7327 - dsctl healthcheck DSMOLE0001 inaccurate recommendations with multiple backends #7328
- Issue 7372 - Reindex adds tombstones to ancestorid causing export failures #7373
- Issue 7437 - LeakSanitizer: memory leaks in CoS cache error paths #7438
- Issue 6922 - AddressSanitizer: leaks found by acl test suite
- Issue 3555 - UI - Fix audit issue with npm - brace-expansion #7556
- Issue 7554 - deref plugin null pointer dereference if ber_init fails
Last modified on 10 September 2026