Input validation error in FreeIPA - CVE-2025-4404
Published: June 30, 2025 / Updated: January 16, 2026
Vulnerability details
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to application fails to validate the uniqueness of the "krbCanonicalName" for the admin account by default. A remote user can create services with the same canonical name as the REALM admin and retrieve a Kerberos ticket in the name of this service, containing the admin@REALM credential.
Affected software
Netezza Appliance
Anolis OS
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
python3-kdcproxy
python3-jwcrypto
custodia
python3-custodia
ipa-healthcheck
ipa-healthcheck-core
slapi-nis
python3-pyusb
python3-yubico
opendnssec
softhsm-devel
softhsm
ipa (Red Hat package)
ipa-server-dns
ipa-server-common
python2-ipalib
python2-ipaserver
python2-ipaclient
ipa-client
ipa-python-compat
ipa-common
ipa-client-common
ipa-server-trust-ad
ipa-server
python3-ipaclient
python3-ipalib
python3-ipaserver
ipa-selinux
python3-ipatests
ipa-client-samba
ipa-client-epn
python3-qrcode-core
python3-qrcode
bind-dyndb-ldap
How to mitigate CVE-2025-4404
Netezza Appliance - update to 1.0.1.0 fp278500
python3-kdcproxy - update to 0.4-5
python3-jwcrypto - update to 0.5.0-2
custodia - update to 0.6.0-3
python3-custodia - update to 0.6.0-3
ipa-healthcheck - addressed in versions 0.12-5, 0.12-6
ipa-healthcheck-core - addressed in versions 0.12-5, 0.12-6
slapi-nis - update to 0.60.0-4.0.1
python3-pyusb - update to 1.0.0-9.1
python3-yubico - update to 1.3.2-9.1
opendnssec - update to 2.1.7-2
softhsm-devel - update to 2.6.0-5
softhsm - update to 2.6.0-5
ipa (Red Hat package) - addressed in versions 4.6.8-5.el7_9.18, 4.9.8-11.el9_0.4, 4.10.1-12.el9_2.4, 4.11.0-15.el9_4.5, 4.12.2-14.el9_6.1, 4.12.2-15.el10_0.1
ipa-server-dns - addressed in versions 4.6.8-5.0.1, 4.9.13-18.0.1, 4.9.13-20.0.1
ipa-server-common - addressed in versions 4.6.8-5.0.1, 4.9.13-18.0.1, 4.9.13-20.0.1
python2-ipalib - update to 4.6.8-5.0.1
python2-ipaserver - update to 4.6.8-5.0.1
python2-ipaclient - update to 4.6.8-5.0.1
ipa-client - addressed in versions 4.6.8-5.0.1, 4.9.13-18.0.1, 4.9.13-20.0.1
ipa-python-compat - addressed in versions 4.6.8-5.0.1, 4.9.13-18.0.1, 4.9.13-20.0.1
ipa-common - addressed in versions 4.6.8-5.0.1, 4.9.13-18.0.1, 4.9.13-20.0.1
ipa-client-common - addressed in versions 4.6.8-5.0.1, 4.9.13-18.0.1, 4.9.13-20.0.1
ipa-server-trust-ad - addressed in versions 4.6.8-5.0.1, 4.9.13-18.0.1, 4.9.13-20.0.1
ipa-server - addressed in versions 4.6.8-5.0.1, 4.9.13-18.0.1, 4.9.13-20.0.1
python3-ipaclient - addressed in versions 4.9.13-18.0.1, 4.9.13-20.0.1
python3-ipalib - addressed in versions 4.9.13-18.0.1, 4.9.13-20.0.1
python3-ipaserver - addressed in versions 4.9.13-18.0.1, 4.9.13-20.0.1
ipa-selinux - addressed in versions 4.9.13-18.0.1, 4.9.13-20.0.1
python3-ipatests - addressed in versions 4.9.13-18.0.1, 4.9.13-20.0.1
ipa-client-samba - addressed in versions 4.9.13-18.0.1, 4.9.13-20.0.1
ipa-client-epn - addressed in versions 4.9.13-18.0.1, 4.9.13-20.0.1
python3-qrcode-core - update to 5.3-1
python3-qrcode - update to 5.3-1
bind-dyndb-ldap - update to 11.6-6
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Privilege escalation in FreeIPA
- Red Hat Enterprise Linux 9 update for ipa
- Red Hat Enterprise Linux 9 update for ipa
- Red Hat Enterprise Linux 9 update for ipa
- Red Hat Enterprise Linux 9 update for ipa
- Red Hat Enterprise Linux 8 update for the idm:DL1 module
- Red Hat Enterprise Linux 7 Extended Lifecycle Support update for ipa
- Red Hat Enterprise Linux 10 update for ipa
- Red Hat Enterprise Linux 8 update for the idm:DL1 module
- Red Hat Enterprise Linux 8 update for the idm:client module
- Red Hat Enterprise Linux 8 update for the idm:DL1 module
- Anolis OS update for idm:DL1 module
- Anolis OS update for ipa
- Anolis OS update for idm:DL1 module
- Red Hat Enterprise Linux 8 update for the idm:DL1 module
- Anolis OS update for ipa
- Multiple vulnerabilities in IBM Netezza Appliance