CVE-2025-14905Disclosure

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in the 389-ds-base server. A heap buffer overflow vulnerability exists in the `schema_attr_enum_callback` function within the `schema.c` file. This occurs because the code incorrectly calculates the buffer size by summing alias string lengths without accounting for additional formatting characters. When a large number of aliases are processed, this oversight can lead to a heap overflow, potentially allowing a remote attacker to cause a Denial of Service (DoS) or achieve Remote Code Execution (RCE).

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • Peaked 5d ago at 1 mentions (2026-02-23); latest day: 1
  • 6 total mentions across 6 days

Deep dive

Activity timeline6 mentions / 6d
00111Mentions · 2026-02-23: 1Mentions · 2026-02-24: 1Mentions · 2026-02-25: 1Mentions · 2026-02-27: 1Mentions · 2026-02-28: 1Mentions · 2026-04-07: 1Patch / Workaround · 2026-02-25: 1Technical Details · 2026-02-23: 1Technical Details · 2026-02-24: 1Technical Details · 2026-02-25: 1Technical Details · 2026-02-27: 1Technical Details · 2026-02-28: 1Technical Details · 2026-04-07: 102-2302-2402-2502-2702-2804-07
Signal classification2 categories
Disclosure
583.3%
Patch
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-231
Disclosure1
2026-02-241
Disclosure1
2026-02-251
Patch1
2026-02-271
Disclosure1
2026-02-281
Disclosure1
2026-04-071
Disclosure1
Full discourse6 posts
  • Ferramentas Linux@Cezar_H_Linux
    Disclosure

    The signal-to-noise ratio in enterprise Linux security just shifted. RLSA-2026:5513 (CVE-2025-14905) turns 389-ds-base into a critical auth bypass vector. Read more: 👉 https://tinyurl.com/573k2btn #Security #RockyLinux https://t.co/hloKtmD5ga

    Post summary

    A new critical auth bypass vulnerability, CVE-2025-14905, affecting 389-ds-base has been disclosed, with a link provided for further details.

    00010192
    1.5K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-14905 A flaw was found in the 389-ds-base server. A heap buffer overflow vulnerability exists in the `schema_attr_enum_callback` function within the `schema.c` file. This o… https://www.cve.org/CVERecord?id=CVE-2025-14905

    Post summary

    The post announces a heap buffer overflow vulnerability (CVE‑2025‑14905) in the 389‑ds‑base server’s `schema_attr_enum_callback` function, with no evidence of exploitation or patch information.

    00010125
    56.5K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2025-14905 (CVSS:7.2, HIGH) is Awaiting Analysis. A flaw was found in the 389-ds-base server. A heap buffer overflow vulnerability exists in the `schema_attr_enum_callbac..https://nvd.nist.gov/vuln/detail/CVE-2025-14905 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The text announces CVE‑2025‑14905, a heap buffer overflow in 389‑ds‑base with a CVSS of 7.2, but does not provide a PoC, exploit, or mitigation details.

    0000070
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2025-14905 (CVSS:7.2, HIGH) is Awaiting Analysis. A flaw was found in the 389-ds-base server. A heap buffer overflow vulnerability exists in the `schema_attr_enum_callbac..https://nvd.nist.gov/vuln/detail/CVE-2025-14905 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    CVE-2025-14905 is a heap buffer overflow vulnerability in 389-ds-base with a CVSS score of 7.2, awaiting analysis and with no PoC, exploit, or patch information provided.

    0000016
    173 followersView on X
  • ThreatCluster@threatcluster
    Patch

    Oracle patches critical 389-ds flaws in Oracle Linux 9 and 10, including CVE-2025-14905 enabling remote code execution and denial of service. Users should apply ELSA-2026-3189 and 3208. https://threatcluster.io/cluster/critical-vulnerabilities-in-oracle-linux-9-and-10-389-ds-res-37724451

    Post summary

    Oracle released patches for critical 389‑ds flaws in Oracle Linux 9 and 10, including CVE‑2025‑14905 that allows remote code execution and denial of service; users should apply ELSA‑2026‑3189 and 3208.

    0000045
    79 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-14905 Heap Buffer Overflow in 389 Directory Server Schema Parsing Mechanism https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-14905

    Post summary

    The text announces CVE-2025-14905, describing a heap buffer overflow in the 389 Directory Server’s schema parsing mechanism, without providing PoC, exploitation, or patch details.

    0000040
    4.0K followersView on X

Explore more