ipa-4.13.4-1.el9_8

エラータID: AXSA:2026-1928:05

Release date: 
Monday, September 28, 2026 - 16:30
Subject: 
ipa-4.13.4-1.el9_8
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
High
Description: 

Cybertrust Japan Co., Ltd. Identity Management (IdM) is a centralized authentication, identity management, and authorization solution for both traditional and cloud-based enterprise environments.

Security Fix(es):

* ipa: FreeIPA: Unauthenticated DoS in `/ipa/i18n_messages` via Unbounded Request Body Read (CVE-2026-73198)
* ipa: FreeIPA: Unauthenticated DoS in `/ipa/migration/migration.py` via Unbounded Request Body Read (CVE-2026-73197)
* FreeIPA: idm: ipa: FreeIPA: Obtaining TGS with impersonating cname through trust relationships (CVE-2026-11861)
* freeipa: ipa: FreeIPA/IdM: Cross-Site Scripting vulnerability allows arbitrary code execution via crafted URL (CVE-2026-18147)
* freeipa: ipa: FreeIPA: trust-fetch-domains uses trust-read ACI to gate a privileged AD trust refresh, allowing unauthorized LDAP writes (CVE-2026-19550)
* ipa: Privilege escalation via krbCanonicalName manipulation due to realm-unaware uniqueness enforcement in FreeIPA LDAP datastore (CVE-2026-13097)
* ipa: freeipa: FreeIPA: unauthenticated LDAP client can obtain administrator credentials via the self-managed-token ACI (CVE-2026-76578)
* freeIPA: idm: freeipa: idp-add eval() reachable before authorization check allows environment disclosure and denial of service (CVE-2026-79678)

Bug Fix(es) and Enhancement(s):

* [Cursor Automated] Include latest fixes in python3-ipatests package [RHEL9.8] (JIRA:RHEL-170987)
* WebUI Hardening [rhel-9.8.z] (JIRA:RHEL-238511)
* ipa-otptoken-import hardening [rhel-9.8.z] (JIRA:RHEL-238519)
* host-mod: handle the password attribute when set with --setattr userpassword= [rhel-9.8.z] (JIRA:RHEL-238523)
* ipa env: support only simple * wildcard [rhel-9.8.z] (JIRA:RHEL-238527)
* ipa-epn: drop_privileges method is mixing uid and gid [rhel-9.8.z] (JIRA:RHEL-238674)
* ipa-migrate: require Replication Administrator privilege [rhel-9.8.z] (JIRA:RHEL-238677)
* ipa-migrate tool is renaming host records & host info in automount information [rhel-9.8.z] (JIRA:RHEL-240767)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-11861
A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Directory users can bypass authentication for FreeIPA services, including the portal, SMB server, and LDAP directory. This is possible by impersonating a client name in the Ticket Granting Service (TGS) due to FreeIPA services not verifying Privilege Attribute Certificate (PAC) certificates. This vulnerability could allow an authenticated Active Directory user to escalate their privileges within the FreeIPA domain.
CVE-2026-13097
A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory server does not properly account for equivalent representations of the same principal name, allowing a user with sufficient LDAP write privileges to create a service principal that impersonates an existing privileged one. This can lead to unauthorized acquisition of Kerberos service tickets for sensitive services, potentially resulting in full domain compromise.
CVE-2026-18147
A flaw was found in FreeIPA. An unauthenticated remote attacker could exploit a DOM Cross-Site Scripting (XSS) vulnerability in the FreeIPA/IdM Web UI password reset page. By enticing a victim to click a specially crafted link and complete a password reset, the attacker could inject and execute arbitrary JavaScript code. This allows the attacker to perform actions within the victim's authenticated session, potentially leading to full administrative control if an IdM administrator is targeted.
CVE-2026-19550
A flaw was found in FreeIPA. The trust-fetch-domains command is gated by a read-only permission on the trust object rather than a trust-administration permission, allowing an authenticated, non-privileged IPA user to trigger a privileged Active Directory trust refresh using an attacker-supplied server and credentials, resulting in unauthorized, attacker-controlled modification of trusted-domain and ID-range identity data in the IPA LDAP directory.
CVE-2026-73197
A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by sending oversized form POST requests to the `/ipa/migration/migration.py` endpoint. This can force the migration handler to read attacker-controlled request bodies fully into memory, leading to increased memory usage, slower request handling, and potential service disruption or denial of service.
CVE-2026-73198
A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vulnerability in the `/ipa/i18n_messages` endpoint by sending an arbitrarily large request body. This can cause the service to consume excessive memory, leading to memory exhaustion, degraded responsiveness, and a denial of service (DoS) condition.
CVE-2026-76578
A flaw was found in FreeIPA. The self-managed OTP token ACI does not require authentication and does not restrict which attributes may be added alongside the token entry. An unauthenticated LDAP client can exploit this, combined with a related flaw in the underlying directory server's ACI evaluation (tracked separately), to create an arbitrary attacker-controlled Kerberos principal and have it added to the administrators group. This allows a remote, unauthenticated attacker to obtain genuine FreeIPA administrator-group membership and perform administrative operations against the directory and, on SID-enabled deployments, other IdM services.
CVE-2026-79678
A flaw was found in FreeIPA's idp-add command, where insufficiently validated --organization/--base-url input reaches a constrained eval() call before the corresponding LDAP access control check is enforced. This allows any authenticated IPA principal, regardless of privilege level, to enumerate and read the environment variables of the affected server process and to cause denial of service via memory exhaustion.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. ipa-4.13.4-1.el9_8.src.rpm
    MD5: 44e89b953ea5dcc274c5023b139c4014
    SHA-256: 11d32eaba3b157d34daf62b00f21fe80d5414edf71ee2896e76bce6960d57dd5
    Size: 46.25 MB

Asianux Server 9 for x86_64
  1. ipa-client-4.13.4-1.el9_8.x86_64.rpm
    MD5: 72d81a3122646456948b9ab75c1d2c84
    SHA-256: 827c489491ad2378100143990d0979bac25ccb1a982780a47d04ec1f169d98e4
    Size: 138.24 kB
  2. ipa-client-common-4.13.4-1.el9_8.noarch.rpm
    MD5: b4140d7f6e1a89b8d549adc079586af9
    SHA-256: bf86ee938fadb38f204f0183592dd888ee95dc30603fc9f88e3d1382294cc0f7
    Size: 43.55 kB
  3. ipa-client-encrypted-dns-4.13.4-1.el9_8.x86_64.rpm
    MD5: 840d311023156d34f284e1f147f580c6
    SHA-256: cc1f2844b1586fa8ddd0f4c3d2da0cb4ea8a54205b438f36f4eb619a46a64267
    Size: 34.32 kB
  4. ipa-client-epn-4.13.4-1.el9_8.x86_64.rpm
    MD5: 71528dc2d09e16b70883d740158c554d
    SHA-256: 15ef927d6a80dae9dddc6f5ee38f303a636ff0b6d82069264e93b18693c77a8b
    Size: 41.91 kB
  5. ipa-client-samba-4.13.4-1.el9_8.x86_64.rpm
    MD5: 97f6b8d116425e894fcf1f5aad84cd52
    SHA-256: 54ca14a2ddf754de89842fa10539858e6d5ed621e1a8dc6509b32c7b6bc36f94
    Size: 37.28 kB
  6. ipa-common-4.13.4-1.el9_8.noarch.rpm
    MD5: efc54ba3ffe23ab0f7603ce971616139
    SHA-256: 4ca89f700bcadfd27e22b2ceefeba237c2e3d9d706d7327426c19dff0ec39f9c
    Size: 821.38 kB
  7. ipa-selinux-4.13.4-1.el9_8.noarch.rpm
    MD5: 77b7b267189e613007860bdadb55f7c9
    SHA-256: 1bec9d26617cff285f1b1388b0f77b9dd4fcd3ac26ed17b1d4ec5a7d30bdbd19
    Size: 38.41 kB
  8. ipa-selinux-luna-4.13.4-1.el9_8.noarch.rpm
    MD5: 99d310d4d2f818faf957939fdea1d386
    SHA-256: 14643bfcdcc61ef666d840d20ecc8bc16c48dc8a27d5fd35c55e58d8007d489f
    Size: 29.09 kB
  9. ipa-selinux-nfast-4.13.4-1.el9_8.noarch.rpm
    MD5: 64898f033b6f7f1d3ba76b7285a3b88a
    SHA-256: eb65d38105a20804aa599f94e65d22ad2e016b97c9b60def9b54f89723f635ec
    Size: 29.12 kB
  10. ipa-server-4.13.4-1.el9_8.x86_64.rpm
    MD5: 95b07756f25278d4021ab914f28c503c
    SHA-256: aa86ecfe9338ce8409ac30524b613e28d532f3c3ce017348e5590bb0f2f5e1c8
    Size: 435.42 kB
  11. ipa-server-common-4.13.4-1.el9_8.noarch.rpm
    MD5: 2d8dc6c9d60d3b5093cc99e1130df50b
    SHA-256: 2991d784e8c14a00992cce4ea285a6a88959767c354bac65ffc001004dd5e7d3
    Size: 2.90 MB
  12. ipa-server-dns-4.13.4-1.el9_8.noarch.rpm
    MD5: c9671d4fe935f68dd28995e8db1c6c21
    SHA-256: 59dc87a7a4350712b79f2f6d0adce974af362c5f9b157b22497697a5600c1998
    Size: 56.19 kB
  13. ipa-server-encrypted-dns-4.13.4-1.el9_8.x86_64.rpm
    MD5: 2ef149af68c0c22a7216a8efdb539488
    SHA-256: 90683bcc938db49c4b35828bf9d039c88043abaeac9c8341c0119d778a53515d
    Size: 34.40 kB
  14. ipa-server-trust-ad-4.13.4-1.el9_8.x86_64.rpm
    MD5: 7e4f376a6a7ef4d9bc3f63b46adac740
    SHA-256: 4b92d9532c63a8a35f474df21fb1cb29a4b45620a56bf98be9e88773a776defa
    Size: 152.27 kB
  15. python3-ipaclient-4.13.4-1.el9_8.noarch.rpm
    MD5: eb67a2adf84a4d00a0f05bfe9e093ab1
    SHA-256: 359d84f1cfb72c3980d589626b9dda72f8e8d7845ce1558e857fbf3801151cf7
    Size: 662.46 kB
  16. python3-ipalib-4.13.4-1.el9_8.noarch.rpm
    MD5: 2a38e6094e78f6d77404046553853683
    SHA-256: 81443a8985cb54091d333343558853e1ee5db52d9d906f8aae4bad3aeb7d7382
    Size: 705.03 kB
  17. python3-ipaserver-4.13.4-1.el9_8.noarch.rpm
    MD5: 3e77ed38dc5bef4bdd9c807612e49b6c
    SHA-256: bd1d196f5292955a80530cbc3a051b9ffd6af78fa0e152b1a952abdc12cee16c
    Size: 1.58 MB
  18. python3-ipatests-4.13.4-1.el9_8.noarch.rpm
    MD5: daf572f73f93bade6cc136ec56a4a33f
    SHA-256: 8537eaa9e2b8f2fe1a2a5d7a4d617dd7f3f18a49a9927132a676ad736743b894
    Size: 2.04 MB