Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:5513 - Security Advisory
Issued:
2026-03-24
Updated:
2026-03-24

RHSA-2026:5513 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: 389-ds:1.4 security update

Type/Severity

Security Advisory: Moderate

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for the 389-ds:1.4 module is now available for Red Hat Enterprise Linux 8.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

389 Directory Server is an LDAP version 3 (LDAPv3) compliant server. The base packages include the Lightweight Directory Access Protocol (LDAP) server and command-line utilities for server administration.

Security Fix(es):

  • 389-ds-base: 389-ds-base: Remote Code Execution and Denial of Service via heap buffer overflow (CVE-2025-14905)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 8 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 8 s390x
  • Red Hat Enterprise Linux for Power, little endian 8 ppc64le
  • Red Hat Enterprise Linux for ARM 64 8 aarch64

Fixes

  • BZ - 2423624 - CVE-2025-14905 389-ds-base: 389-ds-base: Remote Code Execution and Denial of Service via heap buffer overflow

CVEs

  • CVE-2025-14905

References

  • https://access.redhat.com/security/updates/classification/#moderate
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 8

SRPM
389-ds-base-1.4.3.39-23.module+el8.10.0+24085+b368a310.src.rpm SHA-256: 1c3c29b793cf595e8b9d9b92b9ad40f7a571c0a3caaba89e19f1679898a1d7e3
x86_64
python3-lib389-1.4.3.39-23.module+el8.10.0+24085+b368a310.noarch.rpm SHA-256: 3fdc805f13754f2a0fa0f71224ec025c64b956af1ea27ffa2b1b4028638596ad
python3-lib389-1.4.3.39-23.module+el8.10.0+24085+b368a310.noarch.rpm SHA-256: 3fdc805f13754f2a0fa0f71224ec025c64b956af1ea27ffa2b1b4028638596ad
python3-lib389-1.4.3.39-23.module+el8.10.0+24085+b368a310.noarch.rpm SHA-256: 3fdc805f13754f2a0fa0f71224ec025c64b956af1ea27ffa2b1b4028638596ad
389-ds-base-1.4.3.39-23.module+el8.10.0+24085+b368a310.x86_64.rpm SHA-256: 5f2c39fd501ece666714c4bb52ea257da89ed5bdff1a1f2a360446263d421ed7
389-ds-base-debuginfo-1.4.3.39-23.module+el8.10.0+24085+b368a310.x86_64.rpm SHA-256: de2f42fad0f65037534e59b1c916158b692a64b5051524517429fa9d18db1a76
389-ds-base-debugsource-1.4.3.39-23.module+el8.10.0+24085+b368a310.x86_64.rpm SHA-256: 1cc6d29134b8d258cca7128375cf112decb599b4e1837fafa2bd083251799e66
389-ds-base-devel-1.4.3.39-23.module+el8.10.0+24085+b368a310.x86_64.rpm SHA-256: 74d703b24f2e8e610fc3dbb04c07b5b8f92e2c019fd63057a874af204c265fb9
389-ds-base-legacy-tools-1.4.3.39-23.module+el8.10.0+24085+b368a310.x86_64.rpm SHA-256: 0efeb015be29881eb8fcd9724f6c965362b26c039f79b9c4a1865c161984af43
389-ds-base-legacy-tools-debuginfo-1.4.3.39-23.module+el8.10.0+24085+b368a310.x86_64.rpm SHA-256: d92b93dec1371b3f6484f50f0db20ac9e1d8cd2ce74ce52a190a7d5a331688f0
389-ds-base-libs-1.4.3.39-23.module+el8.10.0+24085+b368a310.x86_64.rpm SHA-256: 2961afac4f5865ab4a17df45865b291dd608e2c373540dd7b401e815db271d85
389-ds-base-libs-debuginfo-1.4.3.39-23.module+el8.10.0+24085+b368a310.x86_64.rpm SHA-256: 83750467c96fff4e928978f23d01fdf4d6631344137ea206f09c9c4ec4604a45
389-ds-base-snmp-1.4.3.39-23.module+el8.10.0+24085+b368a310.x86_64.rpm SHA-256: 798400c145b7554248be284ee7ad8d1372a4b43296e3725ca69510cb3b1d264d
389-ds-base-snmp-debuginfo-1.4.3.39-23.module+el8.10.0+24085+b368a310.x86_64.rpm SHA-256: b8ebe09fc2721c6a3ff5d228764a983721f16e1bb0557608c056e9ec81baebba
python3-lib389-1.4.3.39-23.module+el8.10.0+24085+b368a310.noarch.rpm SHA-256: 3fdc805f13754f2a0fa0f71224ec025c64b956af1ea27ffa2b1b4028638596ad

Red Hat Enterprise Linux for IBM z Systems 8

SRPM
389-ds-base-1.4.3.39-23.module+el8.10.0+24085+b368a310.src.rpm SHA-256: 1c3c29b793cf595e8b9d9b92b9ad40f7a571c0a3caaba89e19f1679898a1d7e3
s390x
python3-lib389-1.4.3.39-23.module+el8.10.0+24085+b368a310.noarch.rpm SHA-256: 3fdc805f13754f2a0fa0f71224ec025c64b956af1ea27ffa2b1b4028638596ad
389-ds-base-1.4.3.39-23.module+el8.10.0+24085+b368a310.s390x.rpm SHA-256: 1d902d8618f7661d4872ca058953be202168cf48338e23c4d93b212a6360dc5e
389-ds-base-debuginfo-1.4.3.39-23.module+el8.10.0+24085+b368a310.s390x.rpm SHA-256: 45c03ef60046dd942933b865b76ac870639791c3d4232b56afe6fd0c8d5b2f25
389-ds-base-debugsource-1.4.3.39-23.module+el8.10.0+24085+b368a310.s390x.rpm SHA-256: 6427974192ef1e6d52eb5332ab7bf5e39cb38694b8549a08e300e2eec4079122
389-ds-base-devel-1.4.3.39-23.module+el8.10.0+24085+b368a310.s390x.rpm SHA-256: 285acc9010e19d73bcb9222ec1d5bfc65d09013e42d545063d13f00ab936f15a
389-ds-base-legacy-tools-1.4.3.39-23.module+el8.10.0+24085+b368a310.s390x.rpm SHA-256: b1621f0ef97fc3f89e636ffbc5e65c917730875bd638e48d312a5e7d3f69600e
389-ds-base-legacy-tools-debuginfo-1.4.3.39-23.module+el8.10.0+24085+b368a310.s390x.rpm SHA-256: c7426433d61fe2f484e19d862119c97fa4104a7cc2f466211aba06c55c802d13
389-ds-base-libs-1.4.3.39-23.module+el8.10.0+24085+b368a310.s390x.rpm SHA-256: fe742db5b08b356c6866a41172f7d84429d3ea985b34941bf6aaa1c502a650f5
389-ds-base-libs-debuginfo-1.4.3.39-23.module+el8.10.0+24085+b368a310.s390x.rpm SHA-256: db389c3a31f971f4bf31128c3b53fcbd0ed12c736c64100d6702880d6cf59aa7
389-ds-base-snmp-1.4.3.39-23.module+el8.10.0+24085+b368a310.s390x.rpm SHA-256: 5207c431a69b6c32cb4112d65f0fed60ed5f6c65818ba6d020d8320820e619c1
389-ds-base-snmp-debuginfo-1.4.3.39-23.module+el8.10.0+24085+b368a310.s390x.rpm SHA-256: 17455a0cf259b3c1cff1d6216a471a0633570aab7297078d23d93ea8f97779dc
python3-lib389-1.4.3.39-23.module+el8.10.0+24085+b368a310.noarch.rpm SHA-256: 3fdc805f13754f2a0fa0f71224ec025c64b956af1ea27ffa2b1b4028638596ad
python3-lib389-1.4.3.39-23.module+el8.10.0+24085+b368a310.noarch.rpm SHA-256: 3fdc805f13754f2a0fa0f71224ec025c64b956af1ea27ffa2b1b4028638596ad
python3-lib389-1.4.3.39-23.module+el8.10.0+24085+b368a310.noarch.rpm SHA-256: 3fdc805f13754f2a0fa0f71224ec025c64b956af1ea27ffa2b1b4028638596ad

Red Hat Enterprise Linux for Power, little endian 8

SRPM
389-ds-base-1.4.3.39-23.module+el8.10.0+24085+b368a310.src.rpm SHA-256: 1c3c29b793cf595e8b9d9b92b9ad40f7a571c0a3caaba89e19f1679898a1d7e3
ppc64le
389-ds-base-1.4.3.39-23.module+el8.10.0+24085+b368a310.ppc64le.rpm SHA-256: 97af5b18da2b3a8b505b5d9087971ff5450a89780628bf50662e576a916ae59d
389-ds-base-debuginfo-1.4.3.39-23.module+el8.10.0+24085+b368a310.ppc64le.rpm SHA-256: 8d59c23359469c7639b7d2048f92b700f3eb5fbfdfd567e9e4a7b9083c2c4dd5
389-ds-base-debugsource-1.4.3.39-23.module+el8.10.0+24085+b368a310.ppc64le.rpm SHA-256: f0b90a1ad057257b17a1fc3c457cb65c206d1f7702cea90ac803536713c285ac
389-ds-base-devel-1.4.3.39-23.module+el8.10.0+24085+b368a310.ppc64le.rpm SHA-256: 500b67848f1308ba5d210f40adb61502b135edcd3fe40114b1f374532100ec69
389-ds-base-legacy-tools-1.4.3.39-23.module+el8.10.0+24085+b368a310.ppc64le.rpm SHA-256: 91f9d6f38c51d96fb4f1929de5250df956fef17a1e378ebfeeb0d50b5f93ae10
389-ds-base-legacy-tools-debuginfo-1.4.3.39-23.module+el8.10.0+24085+b368a310.ppc64le.rpm SHA-256: 289391bec386083053793941adc0b6e26510b47f563fc908a0c5bed5726381f2
389-ds-base-libs-1.4.3.39-23.module+el8.10.0+24085+b368a310.ppc64le.rpm SHA-256: e3ea45521b0c4732fb770edeaf51912495b0a4f92ffaad42e12389fbc6120866
389-ds-base-libs-debuginfo-1.4.3.39-23.module+el8.10.0+24085+b368a310.ppc64le.rpm SHA-256: 5fc839b532902018d84a10b85a6bd058dbf35dd8aa0684d6af584d4da8832405
389-ds-base-snmp-1.4.3.39-23.module+el8.10.0+24085+b368a310.ppc64le.rpm SHA-256: 50a44397a61b688ea930a4b5d27712cd0af63156c85c89d8e9646de79395c56c
389-ds-base-snmp-debuginfo-1.4.3.39-23.module+el8.10.0+24085+b368a310.ppc64le.rpm SHA-256: 940fadcf2cf8ed633ea3225512760abb2da0c08714436ea6f82415e4b0797874
python3-lib389-1.4.3.39-23.module+el8.10.0+24085+b368a310.noarch.rpm SHA-256: 3fdc805f13754f2a0fa0f71224ec025c64b956af1ea27ffa2b1b4028638596ad
python3-lib389-1.4.3.39-23.module+el8.10.0+24085+b368a310.noarch.rpm SHA-256: 3fdc805f13754f2a0fa0f71224ec025c64b956af1ea27ffa2b1b4028638596ad
python3-lib389-1.4.3.39-23.module+el8.10.0+24085+b368a310.noarch.rpm SHA-256: 3fdc805f13754f2a0fa0f71224ec025c64b956af1ea27ffa2b1b4028638596ad
python3-lib389-1.4.3.39-23.module+el8.10.0+24085+b368a310.noarch.rpm SHA-256: 3fdc805f13754f2a0fa0f71224ec025c64b956af1ea27ffa2b1b4028638596ad

Red Hat Enterprise Linux for ARM 64 8

SRPM
389-ds-base-1.4.3.39-23.module+el8.10.0+24085+b368a310.src.rpm SHA-256: 1c3c29b793cf595e8b9d9b92b9ad40f7a571c0a3caaba89e19f1679898a1d7e3
aarch64
python3-lib389-1.4.3.39-23.module+el8.10.0+24085+b368a310.noarch.rpm SHA-256: 3fdc805f13754f2a0fa0f71224ec025c64b956af1ea27ffa2b1b4028638596ad
python3-lib389-1.4.3.39-23.module+el8.10.0+24085+b368a310.noarch.rpm SHA-256: 3fdc805f13754f2a0fa0f71224ec025c64b956af1ea27ffa2b1b4028638596ad
389-ds-base-1.4.3.39-23.module+el8.10.0+24085+b368a310.aarch64.rpm SHA-256: 1f3f747a08115922d8a9b617ba57bca46dfee27767830530f3b8d642538fe365
389-ds-base-debuginfo-1.4.3.39-23.module+el8.10.0+24085+b368a310.aarch64.rpm SHA-256: 6549389d3bbb3f0ff6f304aa777766dcd89338bcbf99174c8c9157dc4b862be3
389-ds-base-debugsource-1.4.3.39-23.module+el8.10.0+24085+b368a310.aarch64.rpm SHA-256: fe95ca17fb57a5d3255f812f43b0ee06c406d51818d972c0dd5435c7d054b783
389-ds-base-devel-1.4.3.39-23.module+el8.10.0+24085+b368a310.aarch64.rpm SHA-256: 033c2941700aa360c08466fe62c6e5ac04a7817c25b424060b5ebf34376f8279
389-ds-base-legacy-tools-1.4.3.39-23.module+el8.10.0+24085+b368a310.aarch64.rpm SHA-256: 5c8d7c78d7ff8eb899410086c109e963a99f24ba45007014c5344eb43eb7309a
389-ds-base-legacy-tools-debuginfo-1.4.3.39-23.module+el8.10.0+24085+b368a310.aarch64.rpm SHA-256: d45372c0b5f77e4accdaa607f53cd0f4fe50a3d1517cc57a013056193cf4fc87
389-ds-base-libs-1.4.3.39-23.module+el8.10.0+24085+b368a310.aarch64.rpm SHA-256: f7818090e5df54d88623b3c7cde07f979cb1a1e6c96cc4af6485c651dad50b04
389-ds-base-libs-debuginfo-1.4.3.39-23.module+el8.10.0+24085+b368a310.aarch64.rpm SHA-256: c881a2f3d3aa1f81c9538564bd67b8d977137dcf667ac8c0e6008970a9a15bc7
389-ds-base-snmp-1.4.3.39-23.module+el8.10.0+24085+b368a310.aarch64.rpm SHA-256: 2516af5c3784ec7ee9c56b20ee54d9fecda188e3ed62c2e49c0987134fd3f963
389-ds-base-snmp-debuginfo-1.4.3.39-23.module+el8.10.0+24085+b368a310.aarch64.rpm SHA-256: 15ec49af2232244ef27e8a0ef2c8e6fedc31b5d8d4637df620d4c9ce6191e843
python3-lib389-1.4.3.39-23.module+el8.10.0+24085+b368a310.noarch.rpm SHA-256: 3fdc805f13754f2a0fa0f71224ec025c64b956af1ea27ffa2b1b4028638596ad
python3-lib389-1.4.3.39-23.module+el8.10.0+24085+b368a310.noarch.rpm SHA-256: 3fdc805f13754f2a0fa0f71224ec025c64b956af1ea27ffa2b1b4028638596ad

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility