Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:0913-1

Опубликовано: 18 мар. 2026
Источник: suse-cvrf

Описание

Security update for 389-ds

This update for 389-ds fixes the following issues:

  • CVE-2025-14905: Fixed heap buffer overflow due to improper size calculation in schema_attr_enum_callback callback (bsc#1258727).

Список пакетов

SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS
389-ds-2.2.10~git200.96444f3c3-150500.3.42.1
389-ds-devel-2.2.10~git200.96444f3c3-150500.3.42.1
lib389-2.2.10~git200.96444f3c3-150500.3.42.1
libsvrcore0-2.2.10~git200.96444f3c3-150500.3.42.1
SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS
389-ds-2.2.10~git200.96444f3c3-150500.3.42.1
389-ds-devel-2.2.10~git200.96444f3c3-150500.3.42.1
lib389-2.2.10~git200.96444f3c3-150500.3.42.1
libsvrcore0-2.2.10~git200.96444f3c3-150500.3.42.1
SUSE Linux Enterprise Server 15 SP5-LTSS
389-ds-2.2.10~git200.96444f3c3-150500.3.42.1
389-ds-devel-2.2.10~git200.96444f3c3-150500.3.42.1
lib389-2.2.10~git200.96444f3c3-150500.3.42.1
libsvrcore0-2.2.10~git200.96444f3c3-150500.3.42.1
SUSE Linux Enterprise Server for SAP Applications 15 SP5
389-ds-2.2.10~git200.96444f3c3-150500.3.42.1
389-ds-devel-2.2.10~git200.96444f3c3-150500.3.42.1
lib389-2.2.10~git200.96444f3c3-150500.3.42.1
libsvrcore0-2.2.10~git200.96444f3c3-150500.3.42.1

Описание

A flaw was found in the 389-ds-base server. A heap buffer overflow vulnerability exists in the `schema_attr_enum_callback` function within the `schema.c` file. This occurs because the code incorrectly calculates the buffer size by summing alias string lengths without accounting for additional formatting characters. When a large number of aliases are processed, this oversight can lead to a heap overflow, potentially allowing a remote attacker to cause a Denial of Service (DoS) or achieve Remote Code Execution (RCE).


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:389-ds-2.2.10~git200.96444f3c3-150500.3.42.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:389-ds-devel-2.2.10~git200.96444f3c3-150500.3.42.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:lib389-2.2.10~git200.96444f3c3-150500.3.42.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:libsvrcore0-2.2.10~git200.96444f3c3-150500.3.42.1

Ссылки