Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:17649 - Security Advisory
Issued:
2025-10-09
Updated:
2025-10-09

RHSA-2025:17649 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: ipa security update

Type/Severity

Security Advisory: Important

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for ipa is now available for Red Hat Enterprise Linux 7 Extended Lifecycle Support.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat Identity Management (IdM) is a centralized authentication, identity management, and authorization solution for both traditional and cloud-based enterprise environments.

Security Fix(es):

  • FreeIPA: idm: Privilege escalation from host to domain admin in FreeIPA (CVE-2025-7493)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server - Extended Life Cycle Support 7 x86_64
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7 s390x
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7 ppc64
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7 ppc64le

Fixes

  • BZ - 2389448 - CVE-2025-7493 FreeIPA: idm: Privilege escalation from host to domain admin in FreeIPA

CVEs

  • CVE-2025-7493

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server - Extended Life Cycle Support 7

SRPM
ipa-4.6.8-5.el7_9.23.src.rpm SHA-256: b80c4405dfdf4a07a9bd96764d1f70f88fd2d694edcc96a50ccea9116c6a931b
x86_64
ipa-client-4.6.8-5.el7_9.23.x86_64.rpm SHA-256: 724a76702ff31337b7194db5793d8f238901610af2e2fd9ff7f2c44708fc4e8d
ipa-client-common-4.6.8-5.el7_9.23.noarch.rpm SHA-256: 6d1f50fd5005214973ce11ff4b5f0899ca1cecc81b8535ce3de2d2dc97a0ba36
ipa-common-4.6.8-5.el7_9.23.noarch.rpm SHA-256: 5d0b98561f593b846d8fa1439d0a2fa9a2e064e8cf7e67809dc17dd6bd9ad5d7
ipa-debuginfo-4.6.8-5.el7_9.23.x86_64.rpm SHA-256: 7904e76038488633ff6a844ca181ae6e38b1654bce42cd46e35e5f2d8cfd53cd
ipa-python-compat-4.6.8-5.el7_9.23.noarch.rpm SHA-256: 05f6681352123dfb0eb777375856e5a1e09111a3a5bd9deb640671de21176fa7
ipa-server-4.6.8-5.el7_9.23.x86_64.rpm SHA-256: 6e42d93ef74cf1f93839f4567d11e9d13fe07a654881b9f8fd91959d46fa1f53
ipa-server-common-4.6.8-5.el7_9.23.noarch.rpm SHA-256: 24d65cff87341d1d96b721cad89a73c8dc784dc7a23c8b7df0479a0b92a2c6ac
ipa-server-dns-4.6.8-5.el7_9.23.noarch.rpm SHA-256: a23af1bdf97cb3201f9ac93add6d0c04205942729ca2e43c6d7c32e79453a670
ipa-server-trust-ad-4.6.8-5.el7_9.23.x86_64.rpm SHA-256: 4fd12b8d7943ae9345eef69834a84ff18c4a9d3df2255cef9b1b17f0b6edc113
python2-ipaclient-4.6.8-5.el7_9.23.noarch.rpm SHA-256: 9455abb6ad170ca0bc677a297f8310b23a20aa5cc52fc3d831fc9d4639094a48
python2-ipalib-4.6.8-5.el7_9.23.noarch.rpm SHA-256: a7f3ed635c7da1c7e2df31c95f83a1379b2f128255cee35baede8d596e62392b
python2-ipaserver-4.6.8-5.el7_9.23.noarch.rpm SHA-256: 4ddcf5f62b45cbc50881d441b6a233db07c6d3b8fa31339e54055eee4cf6b44e

Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7

SRPM
ipa-4.6.8-5.el7_9.23.src.rpm SHA-256: b80c4405dfdf4a07a9bd96764d1f70f88fd2d694edcc96a50ccea9116c6a931b
s390x
ipa-client-4.6.8-5.el7_9.23.s390x.rpm SHA-256: dce6161c4e25ba177c99fd54158669b2a297d924457c79ce9cbbee8715690eae
ipa-client-common-4.6.8-5.el7_9.23.noarch.rpm SHA-256: 6d1f50fd5005214973ce11ff4b5f0899ca1cecc81b8535ce3de2d2dc97a0ba36
ipa-common-4.6.8-5.el7_9.23.noarch.rpm SHA-256: 5d0b98561f593b846d8fa1439d0a2fa9a2e064e8cf7e67809dc17dd6bd9ad5d7
ipa-debuginfo-4.6.8-5.el7_9.23.s390x.rpm SHA-256: 4beaefbb0a4153b9ce33bfb33bf0563e321e5ad602cf68d15a665736e24a0e89
ipa-python-compat-4.6.8-5.el7_9.23.noarch.rpm SHA-256: 05f6681352123dfb0eb777375856e5a1e09111a3a5bd9deb640671de21176fa7
python2-ipaclient-4.6.8-5.el7_9.23.noarch.rpm SHA-256: 9455abb6ad170ca0bc677a297f8310b23a20aa5cc52fc3d831fc9d4639094a48
python2-ipalib-4.6.8-5.el7_9.23.noarch.rpm SHA-256: a7f3ed635c7da1c7e2df31c95f83a1379b2f128255cee35baede8d596e62392b

Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7

SRPM
ipa-4.6.8-5.el7_9.23.src.rpm SHA-256: b80c4405dfdf4a07a9bd96764d1f70f88fd2d694edcc96a50ccea9116c6a931b
ppc64
ipa-client-4.6.8-5.el7_9.23.ppc64.rpm SHA-256: 0558db94b76d87c23ba4e5463b9b32503d04661e61aef4d749b24ce7d6847ada
ipa-client-common-4.6.8-5.el7_9.23.noarch.rpm SHA-256: 6d1f50fd5005214973ce11ff4b5f0899ca1cecc81b8535ce3de2d2dc97a0ba36
ipa-common-4.6.8-5.el7_9.23.noarch.rpm SHA-256: 5d0b98561f593b846d8fa1439d0a2fa9a2e064e8cf7e67809dc17dd6bd9ad5d7
ipa-debuginfo-4.6.8-5.el7_9.23.ppc64.rpm SHA-256: 69b6a23ac0f11fc7df1e8504a96e9801966b92710f1a388faa2f132f742e075d
ipa-python-compat-4.6.8-5.el7_9.23.noarch.rpm SHA-256: 05f6681352123dfb0eb777375856e5a1e09111a3a5bd9deb640671de21176fa7
python2-ipaclient-4.6.8-5.el7_9.23.noarch.rpm SHA-256: 9455abb6ad170ca0bc677a297f8310b23a20aa5cc52fc3d831fc9d4639094a48
python2-ipalib-4.6.8-5.el7_9.23.noarch.rpm SHA-256: a7f3ed635c7da1c7e2df31c95f83a1379b2f128255cee35baede8d596e62392b

Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7

SRPM
ipa-4.6.8-5.el7_9.23.src.rpm SHA-256: b80c4405dfdf4a07a9bd96764d1f70f88fd2d694edcc96a50ccea9116c6a931b
ppc64le
ipa-client-4.6.8-5.el7_9.23.ppc64le.rpm SHA-256: 11638298e3a9a1639d4ecb7c796c4273701d495af52d0e5e770f8117462f90de
ipa-client-common-4.6.8-5.el7_9.23.noarch.rpm SHA-256: 6d1f50fd5005214973ce11ff4b5f0899ca1cecc81b8535ce3de2d2dc97a0ba36
ipa-common-4.6.8-5.el7_9.23.noarch.rpm SHA-256: 5d0b98561f593b846d8fa1439d0a2fa9a2e064e8cf7e67809dc17dd6bd9ad5d7
ipa-debuginfo-4.6.8-5.el7_9.23.ppc64le.rpm SHA-256: 5ca38b9c0b7fab158b63118aa9f658c52bdd372eb56660ed62318e96f2a9a939
ipa-python-compat-4.6.8-5.el7_9.23.noarch.rpm SHA-256: 05f6681352123dfb0eb777375856e5a1e09111a3a5bd9deb640671de21176fa7
python2-ipaclient-4.6.8-5.el7_9.23.noarch.rpm SHA-256: 9455abb6ad170ca0bc677a297f8310b23a20aa5cc52fc3d831fc9d4639094a48
python2-ipalib-4.6.8-5.el7_9.23.noarch.rpm SHA-256: a7f3ed635c7da1c7e2df31c95f83a1379b2f128255cee35baede8d596e62392b

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility