UBUNTU-CVE-2026-22185

Source
https://ubuntu.com/security/CVE-2026-22185
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-22185.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2026-22185
Upstream
  • CVE-2026-22185
Published
2026-01-08T00:00:00Z
Modified
2026-01-08T06:15:01.549538Z
Severity
  • 7.0 (High) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

OpenLDAP Lightning Memory-Mapped Database (LMDB) mdb_load contains a heap buffer underflow vulnerability in the readline() function. When processing malformed input, an unsigned offset calculation can underflow a heap pointer, resulting in an out-of-bounds read of one byte before the allocated heap buffer. This may allow a local attacker to cause a denial of service and potentially disclose limited heap memory contents.

References

Affected packages

Ubuntu:20.04:LTS

openldap

Package

Name
openldap
Purl
pkg:deb/ubuntu/openldap@2.4.49+dfsg-2ubuntu1.10?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.4.48+dfsg-1ubuntu1
2.4.48+dfsg-1ubuntu2
2.4.48+dfsg-1ubuntu3
2.4.48+dfsg-1ubuntu4
2.4.49+dfsg-1ubuntu1
2.4.49+dfsg-2ubuntu1
2.4.49+dfsg-2ubuntu1.2
2.4.49+dfsg-2ubuntu1.3
2.4.49+dfsg-2ubuntu1.4
2.4.49+dfsg-2ubuntu1.5
2.4.49+dfsg-2ubuntu1.6
2.4.49+dfsg-2ubuntu1.7
2.4.49+dfsg-2ubuntu1.8
2.4.49+dfsg-2ubuntu1.9
2.4.49+dfsg-2ubuntu1.10

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "2.4.49+dfsg-2ubuntu1.10",
            "binary_name": "ldap-utils"
        },
        {
            "binary_version": "2.4.49+dfsg-2ubuntu1.10",
            "binary_name": "libldap-2.4-2"
        },
        {
            "binary_version": "2.4.49+dfsg-2ubuntu1.10",
            "binary_name": "libldap-common"
        },
        {
            "binary_version": "2.4.49+dfsg-2ubuntu1.10",
            "binary_name": "libldap2-dev"
        },
        {
            "binary_version": "2.4.49+dfsg-2ubuntu1.10",
            "binary_name": "slapd"
        },
        {
            "binary_version": "2.4.49+dfsg-2ubuntu1.10",
            "binary_name": "slapd-contrib"
        },
        {
            "binary_version": "2.4.49+dfsg-2ubuntu1.10",
            "binary_name": "slapd-smbk5pwd"
        },
        {
            "binary_version": "2.4.49+dfsg-2ubuntu1.10",
            "binary_name": "slapi-dev"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-22185.json"

Ubuntu:22.04:LTS

openldap

Package

Name
openldap
Purl
pkg:deb/ubuntu/openldap@2.5.19+dfsg-0ubuntu0.22.04.1?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.5.6+dfsg-1~exp1ubuntu1
2.5.11+dfsg-1~exp1ubuntu1
2.5.11+dfsg-1~exp1ubuntu3
2.5.11+dfsg-1~exp1ubuntu3.1
2.5.12+dfsg-0ubuntu0.22.04.1
2.5.13+dfsg-0ubuntu0.22.04.1
2.5.14+dfsg-0ubuntu0.22.04.1
2.5.14+dfsg-0ubuntu0.22.04.2
2.5.15+dfsg-0ubuntu0.22.04.1
2.5.16+dfsg-0ubuntu0.22.04.1
2.5.16+dfsg-0ubuntu0.22.04.2
2.5.17+dfsg-0ubuntu0.22.04.1
2.5.18+dfsg-0ubuntu0.22.04.1
2.5.18+dfsg-0ubuntu0.22.04.2
2.5.18+dfsg-0ubuntu0.22.04.3
2.5.19+dfsg-0ubuntu0.22.04.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "2.5.19+dfsg-0ubuntu0.22.04.1",
            "binary_name": "ldap-utils"
        },
        {
            "binary_version": "2.5.19+dfsg-0ubuntu0.22.04.1",
            "binary_name": "libldap-2.5-0"
        },
        {
            "binary_version": "2.5.19+dfsg-0ubuntu0.22.04.1",
            "binary_name": "libldap-common"
        },
        {
            "binary_version": "2.5.19+dfsg-0ubuntu0.22.04.1",
            "binary_name": "libldap-dev"
        },
        {
            "binary_version": "2.5.19+dfsg-0ubuntu0.22.04.1",
            "binary_name": "libldap2-dev"
        },
        {
            "binary_version": "2.5.19+dfsg-0ubuntu0.22.04.1",
            "binary_name": "slapd"
        },
        {
            "binary_version": "2.5.19+dfsg-0ubuntu0.22.04.1",
            "binary_name": "slapd-contrib"
        },
        {
            "binary_version": "2.5.19+dfsg-0ubuntu0.22.04.1",
            "binary_name": "slapd-smbk5pwd"
        },
        {
            "binary_version": "2.5.19+dfsg-0ubuntu0.22.04.1",
            "binary_name": "slapi-dev"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-22185.json"

Ubuntu:24.04:LTS

openldap

Package

Name
openldap
Purl
pkg:deb/ubuntu/openldap@2.6.7+dfsg-1~exp1ubuntu8.2?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.6.6+dfsg-1~exp1ubuntu1
2.6.7+dfsg-1~exp1ubuntu1
2.6.7+dfsg-1~exp1ubuntu6
2.6.7+dfsg-1~exp1ubuntu8
2.6.7+dfsg-1~exp1ubuntu8.1
2.6.7+dfsg-1~exp1ubuntu8.2

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "2.6.7+dfsg-1~exp1ubuntu8.2",
            "binary_name": "ldap-utils"
        },
        {
            "binary_version": "2.6.7+dfsg-1~exp1ubuntu8.2",
            "binary_name": "libldap-common"
        },
        {
            "binary_version": "2.6.7+dfsg-1~exp1ubuntu8.2",
            "binary_name": "libldap-dev"
        },
        {
            "binary_version": "2.6.7+dfsg-1~exp1ubuntu8.2",
            "binary_name": "libldap2"
        },
        {
            "binary_version": "2.6.7+dfsg-1~exp1ubuntu8.2",
            "binary_name": "libldap2-dev"
        },
        {
            "binary_version": "2.6.7+dfsg-1~exp1ubuntu8.2",
            "binary_name": "slapd"
        },
        {
            "binary_version": "2.6.7+dfsg-1~exp1ubuntu8.2",
            "binary_name": "slapd-contrib"
        },
        {
            "binary_version": "2.6.7+dfsg-1~exp1ubuntu8.2",
            "binary_name": "slapd-smbk5pwd"
        },
        {
            "binary_version": "2.6.7+dfsg-1~exp1ubuntu8.2",
            "binary_name": "slapi-dev"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-22185.json"

Ubuntu:25.04

openldap

Package

Name
openldap
Purl
pkg:deb/ubuntu/openldap@2.6.9+dfsg-2ubuntu1?arch=source&distro=plucky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.6.8+dfsg-1~exp4ubuntu1
2.6.8+dfsg-1~exp4ubuntu3
2.6.9+dfsg-1~exp2ubuntu1
2.6.9+dfsg-2ubuntu1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "2.6.9+dfsg-2ubuntu1",
            "binary_name": "ldap-utils"
        },
        {
            "binary_version": "2.6.9+dfsg-2ubuntu1",
            "binary_name": "libldap-common"
        },
        {
            "binary_version": "2.6.9+dfsg-2ubuntu1",
            "binary_name": "libldap-dev"
        },
        {
            "binary_version": "2.6.9+dfsg-2ubuntu1",
            "binary_name": "libldap2"
        },
        {
            "binary_version": "2.6.9+dfsg-2ubuntu1",
            "binary_name": "libldap2-dev"
        },
        {
            "binary_version": "2.6.9+dfsg-2ubuntu1",
            "binary_name": "slapd"
        },
        {
            "binary_version": "2.6.9+dfsg-2ubuntu1",
            "binary_name": "slapd-contrib"
        },
        {
            "binary_version": "2.6.9+dfsg-2ubuntu1",
            "binary_name": "slapi-dev"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-22185.json"

Ubuntu:25.10

openldap

Package

Name
openldap
Purl
pkg:deb/ubuntu/openldap@2.6.10+dfsg-1ubuntu2?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.6.9+dfsg-2ubuntu1
2.6.10+dfsg-1ubuntu1
2.6.10+dfsg-1ubuntu2

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "2.6.10+dfsg-1ubuntu2",
            "binary_name": "ldap-utils"
        },
        {
            "binary_version": "2.6.10+dfsg-1ubuntu2",
            "binary_name": "libldap-common"
        },
        {
            "binary_version": "2.6.10+dfsg-1ubuntu2",
            "binary_name": "libldap-dev"
        },
        {
            "binary_version": "2.6.10+dfsg-1ubuntu2",
            "binary_name": "libldap2"
        },
        {
            "binary_version": "2.6.10+dfsg-1ubuntu2",
            "binary_name": "libldap2-dev"
        },
        {
            "binary_version": "2.6.10+dfsg-1ubuntu2",
            "binary_name": "slapd"
        },
        {
            "binary_version": "2.6.10+dfsg-1ubuntu2",
            "binary_name": "slapd-contrib"
        },
        {
            "binary_version": "2.6.10+dfsg-1ubuntu2",
            "binary_name": "slapi-dev"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-22185.json"

Ubuntu:Pro:14.04:LTS

openldap

Package

Name
openldap
Purl
pkg:deb/ubuntu/openldap@2.4.31-1+nmu2ubuntu8.5+esm8?arch=source&distro=esm-infra-legacy/trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.4.31-1+nmu2ubuntu3
2.4.31-1+nmu2ubuntu4
2.4.31-1+nmu2ubuntu5
2.4.31-1+nmu2ubuntu8
2.4.31-1+nmu2ubuntu8.1
2.4.31-1+nmu2ubuntu8.2
2.4.31-1+nmu2ubuntu8.3
2.4.31-1+nmu2ubuntu8.4
2.4.31-1+nmu2ubuntu8.5
2.4.31-1+nmu2ubuntu8.5+esm1
2.4.31-1+nmu2ubuntu8.5+esm2
2.4.31-1+nmu2ubuntu8.5+esm3
2.4.31-1+nmu2ubuntu8.5+esm4
2.4.31-1+nmu2ubuntu8.5+esm5
2.4.31-1+nmu2ubuntu8.5+esm6
2.4.31-1+nmu2ubuntu8.5+esm7
2.4.31-1+nmu2ubuntu8.5+esm8

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "2.4.31-1+nmu2ubuntu8.5+esm8",
            "binary_name": "ldap-utils"
        },
        {
            "binary_version": "2.4.31-1+nmu2ubuntu8.5+esm8",
            "binary_name": "libldap-2.4-2"
        },
        {
            "binary_version": "2.4.31-1+nmu2ubuntu8.5+esm8",
            "binary_name": "libldap2-dev"
        },
        {
            "binary_version": "2.4.31-1+nmu2ubuntu8.5+esm8",
            "binary_name": "slapd"
        },
        {
            "binary_version": "2.4.31-1+nmu2ubuntu8.5+esm8",
            "binary_name": "slapd-smbk5pwd"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-22185.json"

Ubuntu:Pro:16.04:LTS

openldap

Package

Name
openldap
Purl
pkg:deb/ubuntu/openldap@2.4.42+dfsg-2ubuntu3.13+esm2?arch=source&distro=esm-infra/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.4.41+dfsg-1ubuntu2
2.4.41+dfsg-1ubuntu3
2.4.42+dfsg-2ubuntu1
2.4.42+dfsg-2ubuntu3
2.4.42+dfsg-2ubuntu3.1
2.4.42+dfsg-2ubuntu3.2
2.4.42+dfsg-2ubuntu3.3
2.4.42+dfsg-2ubuntu3.4
2.4.42+dfsg-2ubuntu3.5
2.4.42+dfsg-2ubuntu3.6
2.4.42+dfsg-2ubuntu3.7
2.4.42+dfsg-2ubuntu3.8
2.4.42+dfsg-2ubuntu3.9
2.4.42+dfsg-2ubuntu3.10
2.4.42+dfsg-2ubuntu3.11
2.4.42+dfsg-2ubuntu3.12
2.4.42+dfsg-2ubuntu3.13
2.4.42+dfsg-2ubuntu3.13+esm1
2.4.42+dfsg-2ubuntu3.13+esm2

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "2.4.42+dfsg-2ubuntu3.13+esm2",
            "binary_name": "ldap-utils"
        },
        {
            "binary_version": "2.4.42+dfsg-2ubuntu3.13+esm2",
            "binary_name": "libldap-2.4-2"
        },
        {
            "binary_version": "2.4.42+dfsg-2ubuntu3.13+esm2",
            "binary_name": "libldap2-dev"
        },
        {
            "binary_version": "2.4.42+dfsg-2ubuntu3.13+esm2",
            "binary_name": "slapd"
        },
        {
            "binary_version": "2.4.42+dfsg-2ubuntu3.13+esm2",
            "binary_name": "slapd-smbk5pwd"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-22185.json"

Ubuntu:Pro:18.04:LTS

openldap

Package

Name
openldap
Purl
pkg:deb/ubuntu/openldap@2.4.45+dfsg-1ubuntu1.11+esm1?arch=source&distro=esm-infra/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.4.45+dfsg-1ubuntu1
2.4.45+dfsg-1ubuntu1.1
2.4.45+dfsg-1ubuntu1.2
2.4.45+dfsg-1ubuntu1.3
2.4.45+dfsg-1ubuntu1.4
2.4.45+dfsg-1ubuntu1.5
2.4.45+dfsg-1ubuntu1.6
2.4.45+dfsg-1ubuntu1.7
2.4.45+dfsg-1ubuntu1.8
2.4.45+dfsg-1ubuntu1.9
2.4.45+dfsg-1ubuntu1.10
2.4.45+dfsg-1ubuntu1.11
2.4.45+dfsg-1ubuntu1.11+esm1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "2.4.45+dfsg-1ubuntu1.11+esm1",
            "binary_name": "ldap-utils"
        },
        {
            "binary_version": "2.4.45+dfsg-1ubuntu1.11+esm1",
            "binary_name": "libldap-2.4-2"
        },
        {
            "binary_version": "2.4.45+dfsg-1ubuntu1.11+esm1",
            "binary_name": "libldap-common"
        },
        {
            "binary_version": "2.4.45+dfsg-1ubuntu1.11+esm1",
            "binary_name": "libldap2-dev"
        },
        {
            "binary_version": "2.4.45+dfsg-1ubuntu1.11+esm1",
            "binary_name": "slapd"
        },
        {
            "binary_version": "2.4.45+dfsg-1ubuntu1.11+esm1",
            "binary_name": "slapd-smbk5pwd"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-22185.json"