CVE-2025-2487: Red Hat Directory Server 12

Medium severity, CVSS 4.9. EPSS: 0.6% chance of exploitation in the next 30 days.

A flaw was found in the 389-ds-base LDAP Server. This issue occurs when issuing a Modify DN LDAP operation through the ldap protocol, when the function return value is not tested and a NULL pointer is dereferenced. If a privileged user performs a ldap MODDN operation after a failed operation, it could lead to a Denial of Service (DoS) or system crash.

Affected products

  • Red Hat Red Hat Directory Server 12
  • Red Hat Red Hat Directory Server 12.4 Eus For Rhel 9: before 9040020250325181857.1674d574 (fixed in 9040020250325181857.1674d574)
  • Red Hat Red Hat Enterprise Linux 10
  • Red Hat Red Hat Enterprise Linux 6
  • Red Hat Red Hat Enterprise Linux 7
  • Red Hat Red Hat Enterprise Linux 8
  • Red Hat Red Hat Enterprise Linux 9: before 0:2.5.2-9.el9_5 (fixed in 0:2.5.2-9.el9_5); before 0:2.6.1-8.el9_6 (fixed in 0:2.6.1-8.el9_6)
  • Red Hat Red Hat Enterprise Linux 9.4 Extended Update Support: before 0:2.4.5-14.el9_4 (fixed in 0:2.4.5-14.el9_4)

Published 2025-03-18. Last modified 2026-06-30.