Описание
Security update for 389-ds
This update for 389-ds fixes the following issues:
- CVE-2025-14905: Fixed heap buffer overflow due to improper size calculation in
schema_attr_enum_callbackcallback (bsc#1258727).
Список пакетов
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS
389-ds-2.2.10~git200.96444f3c3-150500.3.42.1
389-ds-devel-2.2.10~git200.96444f3c3-150500.3.42.1
lib389-2.2.10~git200.96444f3c3-150500.3.42.1
libsvrcore0-2.2.10~git200.96444f3c3-150500.3.42.1
SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS
389-ds-2.2.10~git200.96444f3c3-150500.3.42.1
389-ds-devel-2.2.10~git200.96444f3c3-150500.3.42.1
lib389-2.2.10~git200.96444f3c3-150500.3.42.1
libsvrcore0-2.2.10~git200.96444f3c3-150500.3.42.1
SUSE Linux Enterprise Server 15 SP5-LTSS
389-ds-2.2.10~git200.96444f3c3-150500.3.42.1
389-ds-devel-2.2.10~git200.96444f3c3-150500.3.42.1
lib389-2.2.10~git200.96444f3c3-150500.3.42.1
libsvrcore0-2.2.10~git200.96444f3c3-150500.3.42.1
SUSE Linux Enterprise Server for SAP Applications 15 SP5
389-ds-2.2.10~git200.96444f3c3-150500.3.42.1
389-ds-devel-2.2.10~git200.96444f3c3-150500.3.42.1
lib389-2.2.10~git200.96444f3c3-150500.3.42.1
libsvrcore0-2.2.10~git200.96444f3c3-150500.3.42.1
Ссылки
- Link for SUSE-SU-2026:0913-1
- E-Mail link for SUSE-SU-2026:0913-1
- SUSE Security Ratings
- SUSE Bug 1258727
- SUSE CVE CVE-2025-14905 page
Описание
A flaw was found in the 389-ds-base server. A heap buffer overflow vulnerability exists in the `schema_attr_enum_callback` function within the `schema.c` file. This occurs because the code incorrectly calculates the buffer size by summing alias string lengths without accounting for additional formatting characters. When a large number of aliases are processed, this oversight can lead to a heap overflow, potentially allowing a remote attacker to cause a Denial of Service (DoS) or achieve Remote Code Execution (RCE).
Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:389-ds-2.2.10~git200.96444f3c3-150500.3.42.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:389-ds-devel-2.2.10~git200.96444f3c3-150500.3.42.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:lib389-2.2.10~git200.96444f3c3-150500.3.42.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:libsvrcore0-2.2.10~git200.96444f3c3-150500.3.42.1
Ссылки
- CVE-2025-14905
- SUSE Bug 1258727