Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 1.1%top 37%

CVE-2025-14905: Heap-based Buffer Overflow in Red Hat Red Hat Directory Server 11.5 E4S for RHEL 8

0
High
VulnerabilityCVE-2025-14905cvecve-2025-14905
Published: 02/23/2026 (02/23/2026, 15:41:47 UTC)
Source: CVE Database V5
Vendor/Project: Red Hat
Product: Red Hat Directory Server 11.5 E4S for RHEL 8

Description

A flaw was found in the 389-ds-base server. A heap buffer overflow vulnerability exists in the `schema_attr_enum_callback` function within the `schema.c` file. This occurs because the code incorrectly calculates the buffer size by summing alias string lengths without accounting for additional formatting characters. When a large number of aliases are processed, this oversight can lead to a heap overflow, potentially allowing a remote attacker to cause a Denial of Service (DoS) or achieve Remote Code Execution (RCE).

CVSS v3.1

Score 7.2high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Affected software

redhat/389-ds-base
pkg:rpm/redhat/389-ds-base
Affected versions
>=9.0.0 <9.8>=10.0.0 <10.2

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/02/2026, 22:16:24 UTC

Technical Analysis

A heap buffer overflow vulnerability exists in the schema_attr_enum_callback function of the 389-ds-base server component in Red Hat Directory Server 11.5 E4S for RHEL 8. The vulnerability arises because the code sums alias string lengths without accounting for additional formatting characters, causing an incorrect buffer size calculation. When processing a large number of aliases, this can lead to a heap overflow, enabling a remote attacker to cause Denial of Service or potentially execute arbitrary code remotely. Red Hat has issued security advisories RHSA-2026:3189 and RHSA-2026:3208 with updated 389-ds-base packages that fix this issue for Red Hat Enterprise Linux 9 and 10 respectively. The vulnerability affects versions >=9.0.0 <9.8 and >=10.0.0 <10.2 of the 389-ds-base package. The CVSS score is 7.2 (AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H), reflecting high impact on confidentiality, integrity, and availability.

Potential Impact

Successful exploitation of this heap buffer overflow vulnerability can allow a remote attacker with high privileges to cause a Denial of Service or achieve Remote Code Execution on affected systems running vulnerable versions of 389-ds-base. The vulnerability impacts confidentiality, integrity, and availability of the affected server. No known exploits in the wild have been reported at this time.

Mitigation Recommendations

Red Hat has released official security updates that fix this vulnerability. Users should apply the updated 389-ds-base packages provided in Red Hat Enterprise Linux 9.8 and 10.2 or later as detailed in advisories RHSA-2026:3189 and RHSA-2026:3208. Refer to Red Hat's official article https://access.redhat.com/articles/11258 for update instructions. No additional mitigations are required once the update is applied.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
redhat
Date Reserved
2025-12-18T18:06:35.400Z
Cvss Version
3.1
State
PUBLISHED
Vendor Advisory Urls
[{"url":"https://access.redhat.com/errata/RHSA-2026:3189","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:3208","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:3379","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:3504","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:4207","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:4661","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:4720","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:5196","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:5511","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:5512","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:5513","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:5514","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:5568","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:5569","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:5576","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:5597","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:5598","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:6220","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:6268","vendor":"Red Hat"},{"url":"https://access.redhat.com/security/cve/CVE-2025-14905","vendor":"Red Hat"}]

Threat ID: 699c7b9bbe58cf853ba52827

Added to database: 02/23/2026, 16:08:59 UTC

Last enriched: 07/02/2026, 22:16:24 UTC

Last updated: 07/31/2026, 19:22:53 UTC

Views: 258

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses