{"id":"CVE-2025-2487","summary":"389-ds-base: null pointer dereference leads to denial of service","details":"A flaw was found in the 389-ds-base LDAP Server. This issue occurs when issuing a Modify DN LDAP operation through the ldap protocol, when the function return value is not tested and a NULL pointer is dereferenced. If a privileged user performs a ldap MODDN operation after a failed operation, it could lead to a Denial of Service (DoS) or system crash.","aliases":["GHSA-426r-w669-66gw"],"modified":"2026-08-12T03:30:47.871555297Z","published":"2025-03-18T16:25:43.712Z","related":["ALSA-2025:4491","ALSA-2025:7395","openSUSE-SU-2025:14934-1"],"database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/2xxx/CVE-2025-2487.json","cna_assigner":"redhat","cwe_ids":["CWE-476"]},"references":[{"type":"WEB","url":"https://access.redhat.com/downloads/content/package-browser/"},{"type":"WEB","url":"https://github.com/389ds/389-ds-base/"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2025:3663"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2025:3670"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2025:4491"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2025:7395"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2025-2487"},{"type":"ADVISORY","url":"https://github.com/389ds/389-ds-base/security/advisories/GHSA-426r-w669-66gw"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/2xxx/CVE-2025-2487.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-2487"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2353071"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/389ds/389-ds-base","events":[{"introduced":"87efeb29ab66c826c6a7f0455c6ea244a6e85710"},{"last_affected":"84d6ae0f4a21477644a3defa3a51f5ad8230e418"},{"introduced":"0"},{"last_affected":"b7c575e5264237adcf9019048e02ac2c3a427622"},{"last_affected":"66a9ee1c2eead76dcfbe5dbc3f0309ec3b50cf24"},{"introduced":"d2e54ccd9c571e1326301fc72410bf166fb44067"},{"last_affected":"5864298f44e5a1e18e20ffbb7748d58f45c69b0c"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"2.4.0"},{"last_affected":"2.4.6"},{"introduced":"2.5.0"},{"last_affected":"2.5.3"},{"introduced":"3.0.0"},{"last_affected":"3.0.6"},{"introduced":"2.6.0"},{"last_affected":"2.6.1"}]}}],"versions":["389-ds-base-2.6.1","389-ds-base-3.0.6","389-ds-base-2.5.3","389-ds-base-2.6.0","389-ds-base-3.0.5","389-ds-base-2.4.6","389-ds-base-3.0.4","389-ds-base-2.5.2","389-ds-base-2.5.1","389-ds-base-3.0.3","389-ds-base-3.0.2","389-ds-base-3.0.1","389-ds-base-2.4.0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-2487.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"}]}