VDB
ALSA-2025%3A7395
ALSA-2025%3A7395
PUBLISHED
389 Directory Server is an LDAP version 3 (LDAPv3) compliant server. The base packages include the Lightweight Directory Access Protocol (LDAP) server and command-line utilities for server administration. Security Fix(es): * 389-ds-base: null pointer dereference leads to denial of service (CVE-2025-2487) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| AlmaLinux:9 | 389-ds-base-devel | 0, 0 |
| AlmaLinux:9 | 389-ds-base-snmp | 0, 0 |
| AlmaLinux:9 | python3-lib389 | 0, 0 |
| AlmaLinux:9 | 389-ds-base-libs | 0, 0 |
| AlmaLinux:9 | 389-ds-base | 0, 0 |
Timeline
- May 13, 2025 CVE Published
- May 26, 2025 CVE Updated
- Mar 6, 2026 Distribution Patch
- Mar 6, 2026 Distribution Patch
- Mar 6, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2025:7395 vendor-advisory
- https://access.redhat.com/security/cve/CVE-2025-2487 third-party-advisory
- https://bugzilla.redhat.com/2353071 third-party-advisory
- https://errata.almalinux.org/9/ALSA-2025-7395.html vendor-advisory