Input validation error in FreeIPA - CVE-2025-4404

 

Input validation error in FreeIPA - CVE-2025-4404

Published: June 30, 2025 / Updated: January 16, 2026


Vulnerability identifier: #VU112054
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N]
CVE-ID: CVE-2025-4404
CWE-ID: CWE-20
Exploitation vector: Adjecent network
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote user to escalate privileges.

The vulnerability exists due to application fails to validate the uniqueness of the "krbCanonicalName" for the admin account by default. A remote user can create services with the same canonical name as the REALM admin and retrieve a Kerberos ticket in the name of this service, containing the admin@REALM credential. 


Affected software

FreeIPA
Netezza Appliance
Anolis OS
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
python3-kdcproxy
python3-jwcrypto
custodia
python3-custodia
ipa-healthcheck
ipa-healthcheck-core
slapi-nis
python3-pyusb
python3-yubico
opendnssec
softhsm-devel
softhsm
ipa (Red Hat package)
ipa-server-dns
ipa-server-common
python2-ipalib
python2-ipaserver
python2-ipaclient
ipa-client
ipa-python-compat
ipa-common
ipa-client-common
ipa-server-trust-ad
ipa-server
python3-ipaclient
python3-ipalib
python3-ipaserver
ipa-selinux
python3-ipatests
ipa-client-samba
ipa-client-epn
python3-qrcode-core
python3-qrcode
bind-dyndb-ldap

How to mitigate CVE-2025-4404

Install updates from vendor's website.

FreeIPA - update to 4.12.4
Netezza Appliance - update to 1.0.1.0 fp278500
python3-kdcproxy - update to 0.4-5
python3-jwcrypto - update to 0.5.0-2
custodia - update to 0.6.0-3
python3-custodia - update to 0.6.0-3
ipa-healthcheck - addressed in versions 0.12-5, 0.12-6
ipa-healthcheck-core - addressed in versions 0.12-5, 0.12-6
slapi-nis - update to 0.60.0-4.0.1
python3-pyusb - update to 1.0.0-9.1
python3-yubico - update to 1.3.2-9.1
opendnssec - update to 2.1.7-2
softhsm-devel - update to 2.6.0-5
softhsm - update to 2.6.0-5
ipa (Red Hat package) - addressed in versions 4.6.8-5.el7_9.18, 4.9.8-11.el9_0.4, 4.10.1-12.el9_2.4, 4.11.0-15.el9_4.5, 4.12.2-14.el9_6.1, 4.12.2-15.el10_0.1
ipa-server-dns - addressed in versions 4.6.8-5.0.1, 4.9.13-18.0.1, 4.9.13-20.0.1
ipa-server-common - addressed in versions 4.6.8-5.0.1, 4.9.13-18.0.1, 4.9.13-20.0.1
python2-ipalib - update to 4.6.8-5.0.1
python2-ipaserver - update to 4.6.8-5.0.1
python2-ipaclient - update to 4.6.8-5.0.1
ipa-client - addressed in versions 4.6.8-5.0.1, 4.9.13-18.0.1, 4.9.13-20.0.1
ipa-python-compat - addressed in versions 4.6.8-5.0.1, 4.9.13-18.0.1, 4.9.13-20.0.1
ipa-common - addressed in versions 4.6.8-5.0.1, 4.9.13-18.0.1, 4.9.13-20.0.1
ipa-client-common - addressed in versions 4.6.8-5.0.1, 4.9.13-18.0.1, 4.9.13-20.0.1
ipa-server-trust-ad - addressed in versions 4.6.8-5.0.1, 4.9.13-18.0.1, 4.9.13-20.0.1
ipa-server - addressed in versions 4.6.8-5.0.1, 4.9.13-18.0.1, 4.9.13-20.0.1
python3-ipaclient - addressed in versions 4.9.13-18.0.1, 4.9.13-20.0.1
python3-ipalib - addressed in versions 4.9.13-18.0.1, 4.9.13-20.0.1
python3-ipaserver - addressed in versions 4.9.13-18.0.1, 4.9.13-20.0.1
ipa-selinux - addressed in versions 4.9.13-18.0.1, 4.9.13-20.0.1
python3-ipatests - addressed in versions 4.9.13-18.0.1, 4.9.13-20.0.1
ipa-client-samba - addressed in versions 4.9.13-18.0.1, 4.9.13-20.0.1
ipa-client-epn - addressed in versions 4.9.13-18.0.1, 4.9.13-20.0.1
python3-qrcode-core - update to 5.3-1
python3-qrcode - update to 5.3-1
bind-dyndb-ldap - update to 11.6-6

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins