CVE-2025-14905: Heap-based Buffer Overflow in Red Hat Red Hat Directory Server 11.5 E4S for RHEL 8
A flaw was found in the 389-ds-base server. A heap buffer overflow vulnerability exists in the `schema_attr_enum_callback` function within the `schema.c` file. This occurs because the code incorrectly calculates the buffer size by summing alias string lengths without accounting for additional formatting characters. When a large number of aliases are processed, this oversight can lead to a heap overflow, potentially allowing a remote attacker to cause a Denial of Service (DoS) or achieve Remote Code Execution (RCE).
AI Analysis
Technical Summary
A heap buffer overflow vulnerability exists in the schema_attr_enum_callback function of the 389-ds-base server component in Red Hat Directory Server 11.5 E4S for RHEL 8. The vulnerability arises because the code sums alias string lengths without accounting for additional formatting characters, causing an incorrect buffer size calculation. When processing a large number of aliases, this can lead to a heap overflow, enabling a remote attacker to cause Denial of Service or potentially execute arbitrary code remotely. Red Hat has issued security advisories RHSA-2026:3189 and RHSA-2026:3208 with updated 389-ds-base packages that fix this issue for Red Hat Enterprise Linux 9 and 10 respectively. The vulnerability affects versions >=9.0.0 <9.8 and >=10.0.0 <10.2 of the 389-ds-base package. The CVSS score is 7.2 (AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H), reflecting high impact on confidentiality, integrity, and availability.
Potential Impact
Successful exploitation of this heap buffer overflow vulnerability can allow a remote attacker with high privileges to cause a Denial of Service or achieve Remote Code Execution on affected systems running vulnerable versions of 389-ds-base. The vulnerability impacts confidentiality, integrity, and availability of the affected server. No known exploits in the wild have been reported at this time.
Mitigation Recommendations
Red Hat has released official security updates that fix this vulnerability. Users should apply the updated 389-ds-base packages provided in Red Hat Enterprise Linux 9.8 and 10.2 or later as detailed in advisories RHSA-2026:3189 and RHSA-2026:3208. Refer to Red Hat's official article https://access.redhat.com/articles/11258 for update instructions. No additional mitigations are required once the update is applied.
CVE-2025-14905: Heap-based Buffer Overflow in Red Hat Red Hat Directory Server 11.5 E4S for RHEL 8
Description
A flaw was found in the 389-ds-base server. A heap buffer overflow vulnerability exists in the `schema_attr_enum_callback` function within the `schema.c` file. This occurs because the code incorrectly calculates the buffer size by summing alias string lengths without accounting for additional formatting characters. When a large number of aliases are processed, this oversight can lead to a heap overflow, potentially allowing a remote attacker to cause a Denial of Service (DoS) or achieve Remote Code Execution (RCE).
CVSS v3.1
Score 7.2high
Affected software
pkg:rpm/redhat/389-ds-baseRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
A heap buffer overflow vulnerability exists in the schema_attr_enum_callback function of the 389-ds-base server component in Red Hat Directory Server 11.5 E4S for RHEL 8. The vulnerability arises because the code sums alias string lengths without accounting for additional formatting characters, causing an incorrect buffer size calculation. When processing a large number of aliases, this can lead to a heap overflow, enabling a remote attacker to cause Denial of Service or potentially execute arbitrary code remotely. Red Hat has issued security advisories RHSA-2026:3189 and RHSA-2026:3208 with updated 389-ds-base packages that fix this issue for Red Hat Enterprise Linux 9 and 10 respectively. The vulnerability affects versions >=9.0.0 <9.8 and >=10.0.0 <10.2 of the 389-ds-base package. The CVSS score is 7.2 (AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H), reflecting high impact on confidentiality, integrity, and availability.
Potential Impact
Successful exploitation of this heap buffer overflow vulnerability can allow a remote attacker with high privileges to cause a Denial of Service or achieve Remote Code Execution on affected systems running vulnerable versions of 389-ds-base. The vulnerability impacts confidentiality, integrity, and availability of the affected server. No known exploits in the wild have been reported at this time.
Mitigation Recommendations
Red Hat has released official security updates that fix this vulnerability. Users should apply the updated 389-ds-base packages provided in Red Hat Enterprise Linux 9.8 and 10.2 or later as detailed in advisories RHSA-2026:3189 and RHSA-2026:3208. Refer to Red Hat's official article https://access.redhat.com/articles/11258 for update instructions. No additional mitigations are required once the update is applied.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2025-12-18T18:06:35.400Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/errata/RHSA-2026:3189","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:3208","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:3379","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:3504","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:4207","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:4661","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:4720","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:5196","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:5511","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:5512","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:5513","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:5514","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:5568","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:5569","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:5576","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:5597","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:5598","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:6220","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:6268","vendor":"Red Hat"},{"url":"https://access.redhat.com/security/cve/CVE-2025-14905","vendor":"Red Hat"}]
Threat ID: 699c7b9bbe58cf853ba52827
Added to database: 02/23/2026, 16:08:59 UTC
Last enriched: 07/02/2026, 22:16:24 UTC
Last updated: 07/31/2026, 19:22:53 UTC
Views: 258
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.