Описание
Security update for 389-ds
This update for 389-ds fixes the following issues:
- CVE-2025-14905: Fixed heap buffer overflow due to improper size calculation in
schema_attr_enum_callbackcallback (bsc#1258727).
Список пакетов
SUSE Linux Enterprise Server 15 SP6-LTSS
389-ds-2.2.10~git200.96444f3c3-150600.8.26.1
389-ds-devel-2.2.10~git200.96444f3c3-150600.8.26.1
lib389-2.2.10~git200.96444f3c3-150600.8.26.1
libsvrcore0-2.2.10~git200.96444f3c3-150600.8.26.1
SUSE Linux Enterprise Server for SAP Applications 15 SP6
389-ds-2.2.10~git200.96444f3c3-150600.8.26.1
389-ds-devel-2.2.10~git200.96444f3c3-150600.8.26.1
lib389-2.2.10~git200.96444f3c3-150600.8.26.1
libsvrcore0-2.2.10~git200.96444f3c3-150600.8.26.1
openSUSE Leap 15.6
389-ds-2.2.10~git200.96444f3c3-150600.8.26.1
389-ds-devel-2.2.10~git200.96444f3c3-150600.8.26.1
389-ds-snmp-2.2.10~git200.96444f3c3-150600.8.26.1
lib389-2.2.10~git200.96444f3c3-150600.8.26.1
libsvrcore0-2.2.10~git200.96444f3c3-150600.8.26.1
Ссылки
- Link for SUSE-SU-2026:0914-1
- E-Mail link for SUSE-SU-2026:0914-1
- SUSE Security Ratings
- SUSE Bug 1258727
- SUSE CVE CVE-2025-14905 page
Описание
A flaw was found in the 389-ds-base server. A heap buffer overflow vulnerability exists in the `schema_attr_enum_callback` function within the `schema.c` file. This occurs because the code incorrectly calculates the buffer size by summing alias string lengths without accounting for additional formatting characters. When a large number of aliases are processed, this oversight can lead to a heap overflow, potentially allowing a remote attacker to cause a Denial of Service (DoS) or achieve Remote Code Execution (RCE).
Затронутые продукты
SUSE Linux Enterprise Server 15 SP6-LTSS:389-ds-2.2.10~git200.96444f3c3-150600.8.26.1
SUSE Linux Enterprise Server 15 SP6-LTSS:389-ds-devel-2.2.10~git200.96444f3c3-150600.8.26.1
SUSE Linux Enterprise Server 15 SP6-LTSS:lib389-2.2.10~git200.96444f3c3-150600.8.26.1
SUSE Linux Enterprise Server 15 SP6-LTSS:libsvrcore0-2.2.10~git200.96444f3c3-150600.8.26.1
Ссылки
- CVE-2025-14905
- SUSE Bug 1258727