This update for 389-ds fixes the following issue:
Update to 389-ds 3.0.6~git249.6688af9b2:
- CVE-2025-14905: heap buffer overflow due to improper size calculation in `schema_attr_enum_callback` can lead to DoS
and RCE (bsc#1258727).
Changelog:
* Issue 7277 - UI - Fix Japanese translation for "Successfully updated group" in Cockpit UI (#7278)
* Issue 7275 - UI - Improve password policy field validation in Cockpit UI (#7276)
* Issue 7279 - UI - Fix typo in export certificate dialog (#7280)
* Issue 7273 - In a chaining environment binding as remote user causes an invalid error in the logs
* Issue 7271 - plugins that create threads need to update active thread count
* Issue 5853 - Update concread to 0.5.10
* Issue 7053 - Remove memberof_del_dn_from_groups from MemberOf plugin (#7064)
* Issue 7223 - Remove integerOrderingMatch requirement for parentid (#7264)
* Issue 7066/7052 - allow password history to be set to zero and remove history
* Issue 7223 - Use lexicographical...
Read the Full Advisory- openSUSE Leap 16.0:
389-ds-3.0.6~git249.6688af9b2-160000.1.1
389-ds-devel-3.0.6~git249.6688af9b2-160000.1.1
389-ds-snmp-3.0.6~git249.6688af9b2-160000.1.1
lib389-3.0.6~git249.6688af9b2-160000.1.1
libsvrcore0-3.0.6~git249.6688af9b2-160000.1.1
* bsc#1258727
References:
* https://www.suse.com/security/cve/CVE-2025-14905.html
Get the latest Linux and open source security news straight to your inbox.