Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Several security issues were fixed in OpenLDAP.. ========================================================================== Ubuntu Security Notice USN-7713-1 August 24, 2025 openldap vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.04 LTS Summary: Several security issues were fixed in OpenLDAP. Software Description: - openldap: Lightweight Directory Access Protocol Details: It was discovered that OpenLDAP incorrectly handled X.509 DN parsing. A remote attacker could possibly use this issue to cause OpenLDAP to crash, resulting in a denial of service. (CVE-2020-36229, CVE-2020-36230) Pasi Saarinen discovered that OpenLDAP incorrectly handled certain short timestamps. A remote attacker could possibly use this issue to cause OpenLDAP to crash, resulting in a denial of service. (CVE-2021-27212) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 LTS slapd 2.4.31-1+nmu2ubuntu8.5+esm8 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7713-1 CVE-2020-36229, CVE-2020-36230, CVE-2021-27212 . This bulletin covers essential security patches for OpenLDAP within Ubuntu 14.04 LTS to address serious Denial of Service vulnerabilities.. Ubuntu OpenLDAP update Denial of Service issues. . Severity: Critical. LinuxSecurity.com Team
Several security issues were fixed in OpenLDAP.. ========================================================================== Ubuntu Security Notice USN-7698-1 August 17, 2025 openldap vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.04 LTS Summary: Several security issues were fixed in OpenLDAP. Software Description: - openldap: Lightweight Directory Access Protocol Details: It was discovered that OpenLDAP incorrectly handled Certificate Exact Assertion processing. A remote attacker could possibly use this issue to cause OpenLDAP to crash, resulting in a denial of service. (CVE-2020-36221) It was discovered that OpenLDAP incorrectly handled saslAuthzTo processing. A remote attacker could use this issue to cause OpenLDAP to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2020-36222, CVE-2020-36224, CVE-2020-36225, CVE-2020-36226) It was discovered that OpenLDAP incorrectly handled Return Filter control handling. A remote attacker could use this issue to cause OpenLDAP to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2020-36223) It was discovered that OpenLDAP incorrectly handled certain cancel operations. A remote attacker could possibly use this issue to cause OpenLDAP to crash, resulting in a denial of service. (CVE-2020-36227) It was discovered that OpenLDAP incorrectly handled Certificate List Extract Assertion processing. A remote attacker could possibly use this issue to cause OpenLDAP to crash, resulting in a denial of service. (CVE-2020-36228) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 LTS slapd 2.4.31-1+nmu2ubuntu8.5+esm7 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7698-1 CVE-2020-36221, CVE-2020-36222, CVE-2020-36223, CVE-2020-36224, CVE-2020-36225, CVE-2020-36226, CVE-2020-36227, CVE-2020-36228 . Key challenges addressed in OpenLDAP for Ubuntu, safeguarding system stability and effectively mitigating DoS vulnerabilities.. OpenLDAP, Ubuntu, Denial of Service, Security Advisory, System Update. . Severity: Important. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-4264 http://linux.oracle.com/errata/ELSA-2024-4264.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: openldap-2.4.46-19.el8_10.i686.rpm openldap-2.4.46-19.el8_10.x86_64.rpm openldap-clients-2.4.46-19.el8_10.x86_64.rpm openldap-devel-2.4.46-19.el8_10.i686.rpm openldap-devel-2.4.46-19.el8_10.x86_64.rpm openldap-servers-2.4.46-19.el8_10.x86_64.rpm aarch64: openldap-2.4.46-19.el8_10.aarch64.rpm openldap-clients-2.4.46-19.el8_10.aarch64.rpm openldap-devel-2.4.46-19.el8_10.aarch64.rpm openldap-servers-2.4.46-19.el8_10.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates//openldap-2.4.46-19.el8_10.src.rpm Related CVEs: CVE-2023-2953 Description of changes: [2.4.46-19] - Bump version to 2.4.46-19 - Resolves: RHEL-34283 - openldap: null pointer dereference in ber_memalloc_x function _______________________________________________ El-errata mailing list
OpenLDAP could be made to crash if it received specially crafted input.. ========================================================================== Ubuntu Security Notice USN-6616-1 January 30, 2024 openldap vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: OpenLDAP could be made to crash if it received specially crafted input. Software Description: - openldap: Lightweight Directory Access Protocol Details: It was discovered that OpenLDAP was not properly performing bounds checks when executing functions related to LDAP URLs. An attacker could possibly use this issue to cause a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS: slapd 2.5.16+dfsg-0ubuntu0.22.04.2 Ubuntu 20.04 LTS: slapd 2.4.49+dfsg-2ubuntu1.10 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6616-1 CVE-2023-2953 Package Information: https://launchpad.net/ubuntu/+source/openldap/2.5.16+dfsg-0ubuntu0.22.04.2 https://launchpad.net/ubuntu/+source/openldap/2.4.49+dfsg-2ubuntu1.10 . Ubuntu Security Notice USN-6617-1 highlights a vulnerability in the OpenSSH package that affects both Ubuntu 22.04 and 20.04 LTS installations.. OpenLDAP Vulnerability, Denial of Service, Ubuntu Security Update. . Severity: Critical. LinuxSecurity.com Team
Null pointer dereference in ber_memalloc_x() function (CVE-2023-2953) References: - https://bugs.mageia.org/show_bug.cgi?id=32073 - https://ubuntu.com/security/notices/USN-6197-1 . MGASA-2023-0252 - Updated openldap packages fix security vulnerability Publication date: 03 Sep 2023 URL: https://advisories.mageia.org/MGASA-2023-0252.html Type: security Affected Mageia releases: 8 CVE: CVE-2023-2953 Null pointer dereference in ber_memalloc_x() function (CVE-2023-2953) References: - https://bugs.mageia.org/show_bug.cgi?id=32073 - https://ubuntu.com/security/notices/USN-6197-1 - https://www.cve.org/CVERecord?id=CVE-2023-2953 SRPMS: - 8/core/openldap-2.4.57-1.3.mga8 . The revised openldap software packages address a significant null pointer vulnerability in Mageia. Refer to MGASA-2023-0252 for comprehensive information and relevant references.. Openldap Security Update,Mageia 2023,Null Pointer Issue,Security Advisory. . LinuxSecurity.com Team
The container bci/golang was updated. The following patches have been included in this update:. SUSE Container Update Advisory: bci/golang ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:1947-1 Container Tags : bci/golang:1.19 , bci/golang:1.19-23.4 Container Release : 23.4 Severity : moderate Type : security References : 1211795 CVE-2023-2953 ----------------------------------------------------------------- The container bci/golang was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:2484-1 Released: Mon Jun 12 08:49:58 2023 Summary: Security update for openldap2 Type: security Severity: moderate References: 1211795,CVE-2023-2953 This update for openldap2 fixes the following issues: - CVE-2023-2953: Fixed null pointer deref in ber_memalloc_x (bsc#1211795). The following package changes have been done: - libldap-data-2.4.46-150200.14.14.1 updated - libldap-2_4-2-2.4.46-150200.14.14.1 updated - container:sles15-image-15.0.0-27.14.68 updated . SUSE Container Update Notification for bci/python offers insights into a critical security enhancement and corrections.. bci/golang Update, SUSE Container Advisory, Security Update, OpenLDAP Patches. . LinuxSecurity.com Team
The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/sle-micro/5.2/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:1944-1 Container Tags : suse/sle-micro/5.2/toolbox:12.1 , suse/sle-micro/5.2/toolbox:12.1-6.2.231 , suse/sle-micro/5.2/toolbox:latest Container Release : 6.2.231 Severity : important Type : security References : 1207712 1210081 1211661 1211795 1212187 CVE-2023-2953 ----------------------------------------------------------------- The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:2484-1 Released: Mon Jun 12 08:49:58 2023 Summary: Security update for openldap2 Type: security Severity: moderate References: 1211795,CVE-2023-2953 This update for openldap2 fixes the following issues: - CVE-2023-2953: Fixed null pointer deref in ber_memalloc_x (bsc#1211795). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:2497-1 Released: Tue Jun 13 15:37:25 2023 Summary: Recommended update for libzypp Type: recommended Severity: important References: 1211661,1212187 This update for libzypp fixes the following issues: - Fix 'Curl error 92' when synchronizing SUSE Manager repositories. [bsc#1212187] - Do not unconditionally release a medium if provideFile failed. [bsc#1211661] ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:2498-1 Released: Tue Jun 13 16:56:33 2023 Summary: Recommended update for gdb Type: recommended Severity: moderate References: 1207712,1210081 This update for gdb fixes the following issues: - Fix license, again (bsc#1210081). - Patches dropped (bsc#1207712): * gdb-container-rh-pkg.patch -Patches added (bsc#1207712): * gdb-testsuite-add-gdb.suse-debranding.exp.patch The following package changes have been done: - gdb-12.1-150100.8.36.1 updated - libldap-2_4-2-2.4.46-150200.14.14.1 updated - libldap-data-2.4.46-150200.14.14.1 updated - libzypp-17.31.13-150200.66.1 updated - container:sles15-image-15.0.0-17.20.147 updated . Include vital updates for suse/sle-micro/5.2/toolbox; Advisory ID: SUSE-CU-2023:1945 addresses critical security enhancements.. SUSE Toolbox Update, OpenLDAP Security Fix, Container Advisory, SUSE Security Update. . Severity: Important. LinuxSecurity.com Team
The container bci/nodejs was updated. The following patches have been included in this update:. SUSE Container Update Advisory: bci/nodejs ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:1884-1 Container Tags : bci/node:16 , bci/node:16-16.3 , bci/nodejs:16 , bci/nodejs:16-16.3 Container Release : 16.3 Severity : moderate Type : security References : 1211795 CVE-2023-2953 ----------------------------------------------------------------- The container bci/nodejs was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:2484-1 Released: Mon Jun 12 08:49:58 2023 Summary: Security update for openldap2 Type: security Severity: moderate References: 1211795,CVE-2023-2953 This update for openldap2 fixes the following issues: - CVE-2023-2953: Fixed null pointer deref in ber_memalloc_x (bsc#1211795). The following package changes have been done: - libldap-data-2.4.46-150200.14.14.1 updated - libldap-2_4-2-2.4.46-150200.14.14.1 updated - container:sles15-image-15.0.0-27.14.67 updated . SUSE Container Update for bci/python features critical updates. Advisory ID: SUSE-CU-2023:1885-1 targets vulnerability.. SUSE Security Advisory, bci/nodejs Patch, Openldap2 Update, Container Security. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.