ELSA-2025-9190

ELSA-2025-9190 - ipa security update

Type:SECURITY
Impact:IMPORTANT
Release Date:2025-06-27

Description


[4.12.2-15.0.1.el10_0.1]
- Set IPAPLATFORM=rhel when build on Oracle Linux [Orabug: 29516674]
- Add bind to ipa-server-common Requires [Orabug: 36518596]

[4.12.2-15.el10_0.1]
- Resolves: RHEL-89908
EMBARGOED CVE-2025-4404 ipa: Privilege escalation from host to domain admin in FreeIPA
- Resolves: RHEL-89144
kdb: ipadb_get_connection() succeeds but returns null LDAP context


Related CVEs


CVE-2025-4404

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 10 (aarch64) ipa-4.12.2-15.0.1.el10_0.1.src.rpm53ac0cd7f3847bd8a8e7e281fcab1d5c628bda7b1d9342990d85b169159936eb-ol10_aarch64_appstream
ipa-4.12.2-15.0.1.el10_0.1.src.rpm53ac0cd7f3847bd8a8e7e281fcab1d5c628bda7b1d9342990d85b169159936eb-ol10_aarch64_codeready_builder
ipa-client-4.12.2-15.0.1.el10_0.1.aarch64.rpme61e0b9516a815fb6804ad5251cdef0d74f3dde2dd11d1e8ed8c1d095a19ec5e-ol10_aarch64_appstream
ipa-client-common-4.12.2-15.0.1.el10_0.1.noarch.rpm4c1c36099b92e981cb8bc308695f38da25c116810382d5d6db80abe37cad01e6-ol10_aarch64_appstream
ipa-client-encrypted-dns-4.12.2-15.0.1.el10_0.1.aarch64.rpm080f13767e717f5aa50e71cf0f98d7ef5536328f063f07ddf78c70ff94251590-ol10_aarch64_appstream
ipa-client-epn-4.12.2-15.0.1.el10_0.1.aarch64.rpm2aee2cfedefaafdc9e80db4c68c66a9ecb699bcaf095253bd91015efc06a6301-ol10_aarch64_appstream
ipa-client-samba-4.12.2-15.0.1.el10_0.1.aarch64.rpmb41648c56259f709746db4d42fbb0e6fe5627484ff8f594c41dcff10e6ba6321-ol10_aarch64_appstream
ipa-common-4.12.2-15.0.1.el10_0.1.noarch.rpm960e1f540a2ab7dadb44d0ed12ca8d8ccb13337434f5b5ec9999a982d1e097ea-ol10_aarch64_appstream
ipa-selinux-4.12.2-15.0.1.el10_0.1.noarch.rpmbdc7498a56c482ad76133e90e302a95addaf51994f4c7dc912482b09e120a05d-ol10_aarch64_appstream
ipa-selinux-luna-4.12.2-15.0.1.el10_0.1.noarch.rpm36c22e86206a3e9bd6abbd4da5bdb0b1110263b97daae79ec211a12da2c3b74d-ol10_aarch64_appstream
ipa-selinux-nfast-4.12.2-15.0.1.el10_0.1.noarch.rpmb13329d4947766f5b4762948031b0b2e165caddbfa274c8fe515f5dd26451e7c-ol10_aarch64_appstream
ipa-server-4.12.2-15.0.1.el10_0.1.aarch64.rpmda729a05c6da05c86d83244f1e4d85a40b32b2d11e389960907904e0201a1022-ol10_aarch64_appstream
ipa-server-common-4.12.2-15.0.1.el10_0.1.noarch.rpmd036c4815dad7d63df27d64b701bf70268fcf4d73d8a1846a933c5c1216eb71f-ol10_aarch64_appstream
ipa-server-dns-4.12.2-15.0.1.el10_0.1.noarch.rpm4f66d5c376f07c735042c376efdc5b7bc0c76fd15a2e71f13c4964af5068907d-ol10_aarch64_appstream
ipa-server-encrypted-dns-4.12.2-15.0.1.el10_0.1.aarch64.rpm99e5e4accb6ea5e4e06d19c05593974d0136d7c85b13ad28ac1e1d06f7a4f2f8-ol10_aarch64_appstream
ipa-server-trust-ad-4.12.2-15.0.1.el10_0.1.aarch64.rpm1b6619d70836aa0ab9247f41b773b51fda1e79a181d253730bb88d4006fff89c-ol10_aarch64_appstream
python3-ipaclient-4.12.2-15.0.1.el10_0.1.noarch.rpm418477e6f2efb654b17651ba45c570081f71aa11e00cd02efff63498d4c0e683-ol10_aarch64_appstream
python3-ipalib-4.12.2-15.0.1.el10_0.1.noarch.rpm65b04dd5b9b79fa5fe47f2c0b44cfd802ebcdca308911469b129c418d2d484e9-ol10_aarch64_appstream
python3-ipaserver-4.12.2-15.0.1.el10_0.1.noarch.rpm948e5289e271654b2cf75b8774776f40a06925472f230e348ce10528920d1773-ol10_aarch64_appstream
python3-ipatests-4.12.2-15.0.1.el10_0.1.noarch.rpm5dae4c775dd9b73b0924f2be756ab2aff4adb1c5a0cfee0a8f82fe4018316f39-ol10_aarch64_codeready_builder
Oracle Linux 10 (x86_64) ipa-4.12.2-15.0.1.el10_0.1.src.rpm53ac0cd7f3847bd8a8e7e281fcab1d5c628bda7b1d9342990d85b169159936eb-ol10_x86_64_appstream
ipa-4.12.2-15.0.1.el10_0.1.src.rpm53ac0cd7f3847bd8a8e7e281fcab1d5c628bda7b1d9342990d85b169159936eb-ol10_x86_64_codeready_builder
ipa-client-4.12.2-15.0.1.el10_0.1.x86_64.rpma8dea899146cadf10a055fcdb4992ee890d7706d8657931ff9eae95907c81af6-ol10_x86_64_appstream
ipa-client-common-4.12.2-15.0.1.el10_0.1.noarch.rpm4c1c36099b92e981cb8bc308695f38da25c116810382d5d6db80abe37cad01e6-ol10_x86_64_appstream
ipa-client-encrypted-dns-4.12.2-15.0.1.el10_0.1.x86_64.rpm3d8867e2849434f49fa1dbb4b6b3cfb9669d997365d6505ff56722b8c926e8cf-ol10_x86_64_appstream
ipa-client-epn-4.12.2-15.0.1.el10_0.1.x86_64.rpm976a6b87f9308382852b19fdeab388a7d443354ed5d43634b33a637a12c43623-ol10_x86_64_appstream
ipa-client-samba-4.12.2-15.0.1.el10_0.1.x86_64.rpmba5553286d0169a5ffda7adb168c14ba24c5485c437bea4e794f7c14b10934af-ol10_x86_64_appstream
ipa-common-4.12.2-15.0.1.el10_0.1.noarch.rpm960e1f540a2ab7dadb44d0ed12ca8d8ccb13337434f5b5ec9999a982d1e097ea-ol10_x86_64_appstream
ipa-selinux-4.12.2-15.0.1.el10_0.1.noarch.rpmbdc7498a56c482ad76133e90e302a95addaf51994f4c7dc912482b09e120a05d-ol10_x86_64_appstream
ipa-selinux-luna-4.12.2-15.0.1.el10_0.1.noarch.rpm36c22e86206a3e9bd6abbd4da5bdb0b1110263b97daae79ec211a12da2c3b74d-ol10_x86_64_appstream
ipa-selinux-nfast-4.12.2-15.0.1.el10_0.1.noarch.rpmb13329d4947766f5b4762948031b0b2e165caddbfa274c8fe515f5dd26451e7c-ol10_x86_64_appstream
ipa-server-4.12.2-15.0.1.el10_0.1.x86_64.rpm919944c170090accf19ef8f1d9c9bbffb4eb3473cb4e229e4867ab5527e27e35-ol10_x86_64_appstream
ipa-server-common-4.12.2-15.0.1.el10_0.1.noarch.rpmd036c4815dad7d63df27d64b701bf70268fcf4d73d8a1846a933c5c1216eb71f-ol10_x86_64_appstream
ipa-server-dns-4.12.2-15.0.1.el10_0.1.noarch.rpm4f66d5c376f07c735042c376efdc5b7bc0c76fd15a2e71f13c4964af5068907d-ol10_x86_64_appstream
ipa-server-encrypted-dns-4.12.2-15.0.1.el10_0.1.x86_64.rpmc2d41ddaea38b5e28a3d4781a53e0c9ff90c49d632443d2dd31e3d7b2f99a8e5-ol10_x86_64_appstream
ipa-server-trust-ad-4.12.2-15.0.1.el10_0.1.x86_64.rpmc030f0c0bc54bcd4fe186e44f0c425b93569b91a368b1cf51f0d316df6c1e73b-ol10_x86_64_appstream
python3-ipaclient-4.12.2-15.0.1.el10_0.1.noarch.rpm418477e6f2efb654b17651ba45c570081f71aa11e00cd02efff63498d4c0e683-ol10_x86_64_appstream
python3-ipalib-4.12.2-15.0.1.el10_0.1.noarch.rpm65b04dd5b9b79fa5fe47f2c0b44cfd802ebcdca308911469b129c418d2d484e9-ol10_x86_64_appstream
python3-ipaserver-4.12.2-15.0.1.el10_0.1.noarch.rpm948e5289e271654b2cf75b8774776f40a06925472f230e348ce10528920d1773-ol10_x86_64_appstream
python3-ipatests-4.12.2-15.0.1.el10_0.1.noarch.rpm5dae4c775dd9b73b0924f2be756ab2aff4adb1c5a0cfee0a8f82fe4018316f39-ol10_x86_64_codeready_builder



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete