Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

openSUSE Leap 16.0 389-ds Important Heap Overflow DoS CVE-2025-14905

opensuse
Calendar Grey March 28, 2026
Dist Opensuse Esm H88
An important update for openSUSE Leap 16.0 addressing a heap overflow in 389-ds regarding CVE-2025-14905.
An update that solves one vulnerability and has one bug fix can now be installed.

Description

This update for 389-ds fixes the following issue:

Update to 389-ds 3.0.6~git249.6688af9b2:

- CVE-2025-14905: heap buffer overflow due to improper size calculation in `schema_attr_enum_callback` can lead to DoS

and RCE (bsc#1258727).

Changelog:

* Issue 7277 - UI - Fix Japanese translation for "Successfully updated group" in Cockpit UI (#7278)

* Issue 7275 - UI - Improve password policy field validation in Cockpit UI (#7276)

* Issue 7279 - UI - Fix typo in export certificate dialog (#7280)

* Issue 7273 - In a chaining environment binding as remote user causes an invalid error in the logs

* Issue 7271 - plugins that create threads need to update active thread count

* Issue 5853 - Update concread to 0.5.10

* Issue 7053 - Remove memberof_del_dn_from_groups from MemberOf plugin (#7064)

* Issue 7223 - Remove integerOrderingMatch requirement for parentid (#7264)

* Issue 7066/7052 - allow password history to be set to zero and remove history

* Issue 7223 - Use lexicographical...

Read the Full Advisory

Patch

Package List

- openSUSE Leap 16.0:

389-ds-3.0.6~git249.6688af9b2-160000.1.1

389-ds-devel-3.0.6~git249.6688af9b2-160000.1.1

389-ds-snmp-3.0.6~git249.6688af9b2-160000.1.1

lib389-3.0.6~git249.6688af9b2-160000.1.1

libsvrcore0-3.0.6~git249.6688af9b2-160000.1.1

References

* bsc#1258727

References:

* https://www.suse.com/security/cve/CVE-2025-14905.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2026:20415-1
Rating: important
Affected Products: openSUSE Leap 16.0 -------------------------------------------------------------

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here