Skip to content

Red Hat Enterprise Linux (389-ds-base): Multiple Vulnerabilities Enable Code Execution

Bottom line: Multiple vulnerabilities in RHEL 389-ds-base allow authenticated attackers to achieve remote code execution and denial-of-service attacks.

Several vulnerabilities have been discovered in Red Hat Enterprise Linux’s Directory Server (389-ds-base) that enable authenticated attackers to execute arbitrary code or cause denial-of-service conditions.

The Federal Office for Information Security in Germany (BSI) has issued a notice via the CERT-Bund reporting system (WID-SEC-2026-2225) regarding vulnerabilities in the 389 Directory Server component of Red Hat Enterprise Linux. An authenticated remote attacker can exploit these vulnerabilities to execute arbitrary code or cause a denial-of-service condition.

The 389 Directory Server (389-ds-base) is a critical component of RHEL infrastructure and is frequently used for centralized directory services and authentication. Since the vulnerabilities require authentication, valid credentials are required first; however, an attacker with such access can inflict significant damage.

CISOs should prioritize patches for affected RHEL systems, particularly in environments where the Directory Server is used for enterprise-wide authentication and directory services. An inventory of all 389-ds-base deployments and their versions is the first prerequisite for risk analysis.


Source: wid.cert-bund.de · Published 7 July 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: