Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-22185

Опубликовано: 07 янв. 2026
Источник: ubuntu
Приоритет: medium

Описание

OpenLDAP Lightning Memory-Mapped Database (LMDB) versions up to and including 0.9.14, prior to commit 8e1fda8, contain a heap buffer underflow in the readline() function of mdb_load. When processing malformed input containing an embedded NUL byte, an unsigned offset calculation can underflow and cause an out-of-bounds read of one byte before the allocated heap buffer. This can cause mdb_load to crash, leading to a limited denial-of-service condition.

РелизСтатусПримечание
devel

deferred

2026-02-16
esm-apps/bionic

deferred

2026-02-16
esm-apps/xenial

deferred

2026-02-16
esm-infra-legacy/trusty

not-affected

code not present
esm-infra/focal

deferred

2026-02-16
jammy

deferred

2026-02-16
noble

deferred

2026-02-16
plucky

ignored

end of life, was needed
questing

deferred

2026-02-16
upstream

released

0.9.70

Показывать по

РелизСтатусПримечание
devel

not-affected

code not compiled
esm-infra-legacy/trusty

not-affected

code not compiled
esm-infra/bionic

not-affected

code not compiled
esm-infra/focal

not-affected

code not compiled
esm-infra/xenial

not-affected

code not compiled
jammy

not-affected

code not compiled
noble

not-affected

code not compiled
plucky

not-affected

code not compiled
questing

not-affected

code not compiled
upstream

needs-triage

Показывать по

Связанные уязвимости

CVSS3: 6.8
redhat
3 месяца назад

OpenLDAP Lightning Memory-Mapped Database (LMDB) versions up to and including 0.9.14, prior to commit 8e1fda8, contain a heap buffer underflow in the readline() function of mdb_load. When processing malformed input containing an embedded NUL byte, an unsigned offset calculation can underflow and cause an out-of-bounds read of one byte before the allocated heap buffer. This can cause mdb_load to crash, leading to a limited denial-of-service condition.

nvd
3 месяца назад

OpenLDAP Lightning Memory-Mapped Database (LMDB) versions up to and including 0.9.14, prior to commit 8e1fda8, contain a heap buffer underflow in the readline() function of mdb_load. When processing malformed input containing an embedded NUL byte, an unsigned offset calculation can underflow and cause an out-of-bounds read of one byte before the allocated heap buffer. This can cause mdb_load to crash, leading to a limited denial-of-service condition.

msrc
3 месяца назад

OpenLDAP <= 2.6.10 LMDB mdb_load Heap Buffer Underflow in readline()

debian
3 месяца назад

OpenLDAP Lightning Memory-Mapped Database (LMDB) versions up to and in ...

suse-cvrf
2 месяца назад

Security update for openldap2_5