Alerts This Week
Warning Icon 1 1,154
Alerts This Week
Warning Icon 1 1,154

SUSE Linux E Server 389-ds Important Heap Overflow Advisory 2026-20927-1

suse
Calendar Grey April 1, 2026
Dist Suse Esm H88
SUSE security advisory for 389-ds addressing important heap buffer overflow issues and recommended updates.
An update that solves one vulnerability can now be installed.

Summary

## This update for 389-ds fixes the following issue: Update to 389-ds 3.0.6~git249.6688af9b2: * CVE-2025-14905: heap buffer overflow due to improper size calculation in `schema_attr_enum_callback` can lead to DoS and RCE (bsc#1258727). Changelog: * Issue 7277 - UI - Fix Japanese translation for "Successfully updated group" in Cockpit UI (#7278) * Issue 7275 - UI - Improve password policy field validation in Cockpit UI (#7276) * Issue 7279 - UI - Fix typo in export certificate dialog (#7280) * Issue 7273 - In a chaining environment binding as remote user causes an invalid error in the logs * Issue 7271 - plugins that create threads need to update active thread count * Issue 5853 - Update concread to 0.5.10 * Issue 7053 - Remove memberof_del_dn_from_groups from MemberOf plugin (#7064)

References

* bsc#1258727

Cross-

* CVE-2025-14905

CVSS scores:

* CVE-2025-14905 ( SUSE ): 8.6

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

* CVE-2025-14905 ( SUSE ): 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

* CVE-2025-14905 ( NVD ): 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Affected Products:

* SUSE Linux Enterprise Server - BCI 16.0

An update that solves one vulnerability can now be installed.

##

* https://www.suse.com/security/cve/CVE-2025-14905.html

* https://bugzilla.suse.com/show_bug.cgi?id=1258727

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:20927-1
Release Date: 2026-03-24T17:50:31Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here