Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:17086 - Security Advisory
Issued:
2025-09-30
Updated:
2025-09-30

RHSA-2025:17086 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: ipa security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for ipa is now available for Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat Identity Management (IdM) is a centralized authentication, identity management, and authorization solution for both traditional and cloud-based enterprise environments.

Security Fix(es):

  • FreeIPA: idm: Privilege escalation from host to domain admin in FreeIPA (CVE-2025-7493)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.0 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0 x86_64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.0 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.0 s390x

Fixes

  • BZ - 2389448 - CVE-2025-7493 FreeIPA: idm: Privilege escalation from host to domain admin in FreeIPA

CVEs

  • CVE-2025-7493

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.0

SRPM
ipa-4.9.8-11.el9_0.5.src.rpm SHA-256: ce83d0ced162e696ff692861af9edd2f518cd02875f8983c2716585a0c1bd321
ppc64le
ipa-client-4.9.8-11.el9_0.5.ppc64le.rpm SHA-256: 60bc342faf54e8f74fbdc90f735fd5821c927fdc924906471be728e907dbc91e
ipa-client-common-4.9.8-11.el9_0.5.noarch.rpm SHA-256: d722b01a734250131171008e6dd348cb3a35b87023f94d7ad1b1a38a34c98608
ipa-client-debuginfo-4.9.8-11.el9_0.5.ppc64le.rpm SHA-256: a9402485f1e96904c6eef775712f3fe3fd446b7691bada588118b9498065b2fc
ipa-client-epn-4.9.8-11.el9_0.5.ppc64le.rpm SHA-256: 2df0cc028cb6926ab6fb02925367c42bbb283e086732e4ee53365dd342c1a2d0
ipa-client-samba-4.9.8-11.el9_0.5.ppc64le.rpm SHA-256: 6791e85eb1316f677aea7215e0409e5542f0e29d4b11e810424a97b6a7b4fcc4
ipa-common-4.9.8-11.el9_0.5.noarch.rpm SHA-256: 90b4eacccaf5e3858c901da22ea42165a55923d02524a7eb97ff3a47fb5dcf7e
ipa-debuginfo-4.9.8-11.el9_0.5.ppc64le.rpm SHA-256: f9b53a49c6180dcbfa518484cbb1bccb11fe3015379f6633d4f96f338c515047
ipa-debugsource-4.9.8-11.el9_0.5.ppc64le.rpm SHA-256: 122514519fa5767ab414d5348ed4322f62d846ca105ccdb74d99ea372e540f56
ipa-selinux-4.9.8-11.el9_0.5.noarch.rpm SHA-256: 241c7bfa58e5dee6b7859326b0c3635ff6f8e14a769583556cb51e091ad883b0
ipa-server-4.9.8-11.el9_0.5.ppc64le.rpm SHA-256: e4f4218a271a69dff384896433f4c540376cc19ae25749629b99784ea1a3e785
ipa-server-common-4.9.8-11.el9_0.5.noarch.rpm SHA-256: f5ad2e24a1665df825192dc1de37a3730febef025e28cbc67bad6513a32bcb4f
ipa-server-debuginfo-4.9.8-11.el9_0.5.ppc64le.rpm SHA-256: 989437af9fb559db830c1251fddd67d8f55d8190e345dfb7722e4180b77144a8
ipa-server-dns-4.9.8-11.el9_0.5.noarch.rpm SHA-256: bb1a7bf290816af417caa3eaa12ee8fa9189961c40a5bcbae9aa2c14dbcf5eb4
ipa-server-trust-ad-4.9.8-11.el9_0.5.ppc64le.rpm SHA-256: c218afc84ed59b0b0eb84564b9a3fb09debf78b63bc3b03e653e85c98220e7aa
ipa-server-trust-ad-debuginfo-4.9.8-11.el9_0.5.ppc64le.rpm SHA-256: 74372163a24a74aa72baaf77bd248b197745309864692d0da2af91fcdb41beb1
python3-ipaclient-4.9.8-11.el9_0.5.noarch.rpm SHA-256: 60c4d69a0f4bc7eac1b6f2184737673229b644e364a88a14df5c4c6437e65ae9
python3-ipalib-4.9.8-11.el9_0.5.noarch.rpm SHA-256: fa5378548700b3ad5cf866971d5c5c111186afed1a17d4e32e89c0cb5bdbb74f
python3-ipaserver-4.9.8-11.el9_0.5.noarch.rpm SHA-256: b0d67644ba75d3ad00829ae068c6a8278cad595538ea94adc0f1aafd54cbd7f4

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0

SRPM
ipa-4.9.8-11.el9_0.5.src.rpm SHA-256: ce83d0ced162e696ff692861af9edd2f518cd02875f8983c2716585a0c1bd321
x86_64
ipa-client-4.9.8-11.el9_0.5.x86_64.rpm SHA-256: 4d762a8e6235bb1d8e79274e04f13cdd9b626696990d05c70a359f1cb36284f2
ipa-client-common-4.9.8-11.el9_0.5.noarch.rpm SHA-256: d722b01a734250131171008e6dd348cb3a35b87023f94d7ad1b1a38a34c98608
ipa-client-debuginfo-4.9.8-11.el9_0.5.x86_64.rpm SHA-256: b492630d38f6a9c999fe258777b038acd8fa6bca57d2520922d4aaa4f06b4e3c
ipa-client-epn-4.9.8-11.el9_0.5.x86_64.rpm SHA-256: 7af10a7e97f86624cffeec89865d82ca2873fec8d37d8a75f24762a320117c0b
ipa-client-samba-4.9.8-11.el9_0.5.x86_64.rpm SHA-256: 6602db59c4c4b39a32aa9f8b3f9052e4fcdbb50ed8335a22ac5f7b0b6ed36118
ipa-common-4.9.8-11.el9_0.5.noarch.rpm SHA-256: 90b4eacccaf5e3858c901da22ea42165a55923d02524a7eb97ff3a47fb5dcf7e
ipa-debuginfo-4.9.8-11.el9_0.5.x86_64.rpm SHA-256: 9365ad75ed4b98fd757692635b8abf114b7175acc1a449903e680d4e8f035b1c
ipa-debugsource-4.9.8-11.el9_0.5.x86_64.rpm SHA-256: 5a45bdad9267564971dc7bc68ef21c5362646501d13050c0bbe62734e5147773
ipa-selinux-4.9.8-11.el9_0.5.noarch.rpm SHA-256: 241c7bfa58e5dee6b7859326b0c3635ff6f8e14a769583556cb51e091ad883b0
ipa-server-4.9.8-11.el9_0.5.x86_64.rpm SHA-256: 65bde9bda5d76913431caf7dd5d52c4403301887f3b516fa2cbd2086e75b0136
ipa-server-common-4.9.8-11.el9_0.5.noarch.rpm SHA-256: f5ad2e24a1665df825192dc1de37a3730febef025e28cbc67bad6513a32bcb4f
ipa-server-debuginfo-4.9.8-11.el9_0.5.x86_64.rpm SHA-256: 5bff428ebe6a62b7efeb523874495a4d91c38bf987bcba8e65edf37b37833b12
ipa-server-dns-4.9.8-11.el9_0.5.noarch.rpm SHA-256: bb1a7bf290816af417caa3eaa12ee8fa9189961c40a5bcbae9aa2c14dbcf5eb4
ipa-server-trust-ad-4.9.8-11.el9_0.5.x86_64.rpm SHA-256: 51cc0c6f5f508b33beb73c3b87d689fb14b309f5ba6c4221747eb7d0bfeb001d
ipa-server-trust-ad-debuginfo-4.9.8-11.el9_0.5.x86_64.rpm SHA-256: b02769478b700d841ce52757b1dbb3384ca0c8a006ff6460a8c5295054a25962
python3-ipaclient-4.9.8-11.el9_0.5.noarch.rpm SHA-256: 60c4d69a0f4bc7eac1b6f2184737673229b644e364a88a14df5c4c6437e65ae9
python3-ipalib-4.9.8-11.el9_0.5.noarch.rpm SHA-256: fa5378548700b3ad5cf866971d5c5c111186afed1a17d4e32e89c0cb5bdbb74f
python3-ipaserver-4.9.8-11.el9_0.5.noarch.rpm SHA-256: b0d67644ba75d3ad00829ae068c6a8278cad595538ea94adc0f1aafd54cbd7f4

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.0

SRPM
ipa-4.9.8-11.el9_0.5.src.rpm SHA-256: ce83d0ced162e696ff692861af9edd2f518cd02875f8983c2716585a0c1bd321
aarch64
ipa-client-4.9.8-11.el9_0.5.aarch64.rpm SHA-256: 2b237d3cd1e0979f75ca952f6c9f17324e3e9a4dd5409c9552583328abf0c3d2
ipa-client-common-4.9.8-11.el9_0.5.noarch.rpm SHA-256: d722b01a734250131171008e6dd348cb3a35b87023f94d7ad1b1a38a34c98608
ipa-client-debuginfo-4.9.8-11.el9_0.5.aarch64.rpm SHA-256: 220bc366c97d4eb930049caf1cd7f165dd77f45c47e8d4e886f3efafe78d8417
ipa-client-epn-4.9.8-11.el9_0.5.aarch64.rpm SHA-256: 934a24fdc99aa9ceaedb990050dc803df6f6c4298658d222962ab34d59da6621
ipa-client-samba-4.9.8-11.el9_0.5.aarch64.rpm SHA-256: e0bd4b42569fc63036573ecc29af596df6b0ab624050d3c23d7a42d672e54fe3
ipa-common-4.9.8-11.el9_0.5.noarch.rpm SHA-256: 90b4eacccaf5e3858c901da22ea42165a55923d02524a7eb97ff3a47fb5dcf7e
ipa-debuginfo-4.9.8-11.el9_0.5.aarch64.rpm SHA-256: 6256e43133b97e68fb2ff3ef401cbcb44b283cf493ad918ceca812d9b4e02589
ipa-debugsource-4.9.8-11.el9_0.5.aarch64.rpm SHA-256: 728ab04672bad89ca46ee85765c7949eec868d5ae1fb02b8e3d2ae876b06b914
ipa-selinux-4.9.8-11.el9_0.5.noarch.rpm SHA-256: 241c7bfa58e5dee6b7859326b0c3635ff6f8e14a769583556cb51e091ad883b0
ipa-server-4.9.8-11.el9_0.5.aarch64.rpm SHA-256: 5fbdc5b80050a43f8d90f993b9ad14c4460a12bac8d50feb32558a89be9eae30
ipa-server-common-4.9.8-11.el9_0.5.noarch.rpm SHA-256: f5ad2e24a1665df825192dc1de37a3730febef025e28cbc67bad6513a32bcb4f
ipa-server-debuginfo-4.9.8-11.el9_0.5.aarch64.rpm SHA-256: 58185455edbdabf0d76257c5ea00a8439a5f583c1b06995926b23a79ce079511
ipa-server-dns-4.9.8-11.el9_0.5.noarch.rpm SHA-256: bb1a7bf290816af417caa3eaa12ee8fa9189961c40a5bcbae9aa2c14dbcf5eb4
ipa-server-trust-ad-4.9.8-11.el9_0.5.aarch64.rpm SHA-256: 673e86c17f189b9d905fb047211d88d398bc222e660a2ca0e9e2961f58442c78
ipa-server-trust-ad-debuginfo-4.9.8-11.el9_0.5.aarch64.rpm SHA-256: 64e561a837cdea593b3c35e5b08effa2b85220dc450e678260e63147de30e57d
python3-ipaclient-4.9.8-11.el9_0.5.noarch.rpm SHA-256: 60c4d69a0f4bc7eac1b6f2184737673229b644e364a88a14df5c4c6437e65ae9
python3-ipalib-4.9.8-11.el9_0.5.noarch.rpm SHA-256: fa5378548700b3ad5cf866971d5c5c111186afed1a17d4e32e89c0cb5bdbb74f
python3-ipaserver-4.9.8-11.el9_0.5.noarch.rpm SHA-256: b0d67644ba75d3ad00829ae068c6a8278cad595538ea94adc0f1aafd54cbd7f4

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.0

SRPM
ipa-4.9.8-11.el9_0.5.src.rpm SHA-256: ce83d0ced162e696ff692861af9edd2f518cd02875f8983c2716585a0c1bd321
s390x
ipa-client-4.9.8-11.el9_0.5.s390x.rpm SHA-256: 526a25f2610e1d6784ee736fe2248420b779a8016840f4f12214b21ad66dab8c
ipa-client-common-4.9.8-11.el9_0.5.noarch.rpm SHA-256: d722b01a734250131171008e6dd348cb3a35b87023f94d7ad1b1a38a34c98608
ipa-client-debuginfo-4.9.8-11.el9_0.5.s390x.rpm SHA-256: 62ea6d3bde6824a857cbbd4acd2e832ad02ba11685a43f3c820cd07a615c4a5d
ipa-client-epn-4.9.8-11.el9_0.5.s390x.rpm SHA-256: 95932d1961540d15435d92ca9d5c8ef9e23803d8ea264c680d35340ec467a6ff
ipa-client-samba-4.9.8-11.el9_0.5.s390x.rpm SHA-256: 6333806023406eb74e3120644cee2fa582d1683e2a22a51d2c4d12ce26829e08
ipa-common-4.9.8-11.el9_0.5.noarch.rpm SHA-256: 90b4eacccaf5e3858c901da22ea42165a55923d02524a7eb97ff3a47fb5dcf7e
ipa-debuginfo-4.9.8-11.el9_0.5.s390x.rpm SHA-256: 9cba9bf98d8aec0496e23a6ea398649ca2612a3628e8555f4c62fee5da82762b
ipa-debugsource-4.9.8-11.el9_0.5.s390x.rpm SHA-256: 9537f90ab235b69fec38b5c8f49cfcbe80897f55f5b23415cf0236c2c63ff939
ipa-selinux-4.9.8-11.el9_0.5.noarch.rpm SHA-256: 241c7bfa58e5dee6b7859326b0c3635ff6f8e14a769583556cb51e091ad883b0
ipa-server-4.9.8-11.el9_0.5.s390x.rpm SHA-256: 0db6f50eae34b8352c95b02fb15aa409db880c3e05351684f1f34abb085440cd
ipa-server-common-4.9.8-11.el9_0.5.noarch.rpm SHA-256: f5ad2e24a1665df825192dc1de37a3730febef025e28cbc67bad6513a32bcb4f
ipa-server-debuginfo-4.9.8-11.el9_0.5.s390x.rpm SHA-256: a6bf0f4e366e136c3f882acb5f432d1e206f32de16dedb933fceee40ed0fa990
ipa-server-dns-4.9.8-11.el9_0.5.noarch.rpm SHA-256: bb1a7bf290816af417caa3eaa12ee8fa9189961c40a5bcbae9aa2c14dbcf5eb4
ipa-server-trust-ad-4.9.8-11.el9_0.5.s390x.rpm SHA-256: 9caf22b835012ddde46d36f793986e579df31bea1a2738c6c3952c8d4222d39c
ipa-server-trust-ad-debuginfo-4.9.8-11.el9_0.5.s390x.rpm SHA-256: 02680c45399720829e7812f3e3876d3f813d572feccffe170f016de7f6721cbc
python3-ipaclient-4.9.8-11.el9_0.5.noarch.rpm SHA-256: 60c4d69a0f4bc7eac1b6f2184737673229b644e364a88a14df5c4c6437e65ae9
python3-ipalib-4.9.8-11.el9_0.5.noarch.rpm SHA-256: fa5378548700b3ad5cf866971d5c5c111186afed1a17d4e32e89c0cb5bdbb74f
python3-ipaserver-4.9.8-11.el9_0.5.noarch.rpm SHA-256: b0d67644ba75d3ad00829ae068c6a8278cad595538ea94adc0f1aafd54cbd7f4

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility