CVE-2025-14905

7.2

Red Hat · 389 Directory Server

A heap-based buffer overflow in the 389 Directory Server schema callback function allows authenticated remote attackers to cause a Denial of Service or achieve Remote Code Execution.

Executive summary

A critical heap buffer overflow vulnerability in the 389 Directory Server allows authenticated attackers to execute arbitrary code or crash the service.

Vulnerability

This is a heap-based buffer overflow (CWE-122) located in the schema_attr_enum_callback function within schema.c. The flaw is triggered by improper buffer size calculations during alias string processing, which requires high-privileged (authenticated) access to the server to exploit.

Business impact

Successful exploitation of this vulnerability poses a severe risk to organizational infrastructure, as it can lead to full system compromise through Remote Code Execution. Given the CVSS score of 7.2, the impact on confidentiality, integrity, and availability is high. An attacker capable of reaching the directory service with administrative privileges could gain unauthorized control over identity management systems, leading to widespread data exposure or operational disruption.

Remediation

Immediate Action: Update the 389 Directory Server packages to the versions specified in the associated Red Hat Security Advisories (RHSA-2026:3189, RHSA-2026:3208, RHSA-2026:3379, RHSA-2026:3504, RHSA-2026:4207, RHSA-2026:4661, RHSA-2026:4720, or RHSA-2026:5196).

Proactive Monitoring: Monitor server logs for suspicious schema modification attempts or service crashes that may indicate an exploitation attempt.

Compensating Controls: Restrict network access to the directory server to known, trusted management segments to limit the attack surface for privileged users.

Exploitation status

Public Exploit Available: No (Unknown)

Analyst recommendation

Organizations running the affected Red Hat Directory Server versions must prioritize applying the provided security patches. Because this vulnerability allows for Remote Code Execution, the risk is substantial. Administrators should verify their current versions against the fixed releases listed in the enrichment data and coordinate deployment to ensure that all directory server instances are secured against potential exploitation.

More Red Hat CVEs

Sources

Originally found and disclosed by This issue was discovered by Red Hat Security Research Team (Red Hat Inc.)., per the CVE Program record.