Описание
Security update for 389-ds
This update for 389-ds fixes the following issues:
Update to LTS branch 2.7 (jsc#PED-14342):
- CVE-2025-14905: Fixed heap buffer overflow due to improper size calculation in
schema_attr_enum_callbackcallback (bsc#1258727).
Bug fixes:
- Resolve python build error that caused lib389 to be missing some libraries. (bsc#1258689)
Список пакетов
SUSE Linux Enterprise Module for Server Applications 15 SP7
389-ds-2.7.0~git144.f597a91d8-150700.3.13.1
389-ds-devel-2.7.0~git144.f597a91d8-150700.3.13.1
lib389-2.7.0~git144.f597a91d8-150700.3.13.1
libsvrcore0-2.7.0~git144.f597a91d8-150700.3.13.1
Ссылки
- Link for SUSE-SU-2026:0915-1
- E-Mail link for SUSE-SU-2026:0915-1
- SUSE Security Ratings
- SUSE Bug 1258689
- SUSE Bug 1258727
- SUSE CVE CVE-2025-14905 page
Описание
A flaw was found in the 389-ds-base server. A heap buffer overflow vulnerability exists in the `schema_attr_enum_callback` function within the `schema.c` file. This occurs because the code incorrectly calculates the buffer size by summing alias string lengths without accounting for additional formatting characters. When a large number of aliases are processed, this oversight can lead to a heap overflow, potentially allowing a remote attacker to cause a Denial of Service (DoS) or achieve Remote Code Execution (RCE).
Затронутые продукты
SUSE Linux Enterprise Module for Server Applications 15 SP7:389-ds-2.7.0~git144.f597a91d8-150700.3.13.1
SUSE Linux Enterprise Module for Server Applications 15 SP7:389-ds-devel-2.7.0~git144.f597a91d8-150700.3.13.1
SUSE Linux Enterprise Module for Server Applications 15 SP7:lib389-2.7.0~git144.f597a91d8-150700.3.13.1
SUSE Linux Enterprise Module for Server Applications 15 SP7:libsvrcore0-2.7.0~git144.f597a91d8-150700.3.13.1
Ссылки
- CVE-2025-14905
- SUSE Bug 1258727