Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:9185 - Security Advisory
Issued:
2025-06-17
Updated:
2025-06-17

RHSA-2025:9185 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: ipa security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for ipa is now available for Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat Identity Management (IdM) is a centralized authentication, identity management, and authorization solution for both traditional and cloud-based enterprise environments.

Security Fix(es):

  • freeIPA: idm: Privilege escalation from host to domain admin in FreeIPA (CVE-2025-4404)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.0 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0 x86_64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.0 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.0 s390x

Fixes

  • BZ - 2364606 - CVE-2025-4404 freeIPA: idm: Privilege escalation from host to domain admin in FreeIPA

CVEs

  • CVE-2025-4404

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.0

SRPM
ipa-4.9.8-11.el9_0.4.src.rpm SHA-256: a5c110f51ccbe76b1e917baaf6d56b7d47a84fb64f274978c3764ba19292bb92
ppc64le
ipa-client-4.9.8-11.el9_0.4.ppc64le.rpm SHA-256: 2e15e81f77c0da69630422dd0dc3eca29d659deb57cb132e775931212391adee
ipa-client-common-4.9.8-11.el9_0.4.noarch.rpm SHA-256: c21fc9da5ded0fd9cb4310f4e9d4f6c55a48765ce07af4f39ca66de8f15ea9d2
ipa-client-debuginfo-4.9.8-11.el9_0.4.ppc64le.rpm SHA-256: d677d9afcfb436cb03a0d326952c0e8ef76bcfc5b557fdad9291313546a9bbf8
ipa-client-epn-4.9.8-11.el9_0.4.ppc64le.rpm SHA-256: 99dae48e7f209969ce405435a161f82f3aa19fdfa4ebb20c8da1f2fea383ae90
ipa-client-samba-4.9.8-11.el9_0.4.ppc64le.rpm SHA-256: ffd7dfd16cdd69dd60768082ced410ad7c15c2d0ca8c1d3e20dd3e99a588bbea
ipa-common-4.9.8-11.el9_0.4.noarch.rpm SHA-256: b848aff43e5ca55849d8a831512a2b4aea15256c6b0d3b9d9b26c87fb7004df8
ipa-debuginfo-4.9.8-11.el9_0.4.ppc64le.rpm SHA-256: 7ba4be916ba9b89f7681174acbd2687bc4328f1e2509621d2dfe79382d974a9c
ipa-debugsource-4.9.8-11.el9_0.4.ppc64le.rpm SHA-256: 9f84aba2279f5a68a36a5c4f3d948f4693574707636534ab5addb7541b6dbb92
ipa-selinux-4.9.8-11.el9_0.4.noarch.rpm SHA-256: 6bb639521a333d32e1639fb810907543025f14e59a96469858bf5bdfc36aaf14
ipa-server-4.9.8-11.el9_0.4.ppc64le.rpm SHA-256: e1b23034a03d3ae367514fc7167b33f0f91d250f655e3ab051a479dc5f3a70b2
ipa-server-common-4.9.8-11.el9_0.4.noarch.rpm SHA-256: fdcdd1a7b2a3bb34ce50efd0cc684bff72cdffbabd1749877c4d33c192dd694c
ipa-server-debuginfo-4.9.8-11.el9_0.4.ppc64le.rpm SHA-256: 7bf3c30557971644f9fdf3d05166871563a2be07fd2b27ff4eb68235dd514e27
ipa-server-dns-4.9.8-11.el9_0.4.noarch.rpm SHA-256: 92d4df95a6598dc3b5eb1c0adaf421634c8a4b24f21bf146e8c07f780046531e
ipa-server-trust-ad-4.9.8-11.el9_0.4.ppc64le.rpm SHA-256: 9080ea490c1142b1a12cdd2c40c7d4240aa1c2f775b3543ad84e37731ab9f68e
ipa-server-trust-ad-debuginfo-4.9.8-11.el9_0.4.ppc64le.rpm SHA-256: 48ac91815ad43ea5d6422060b58e1b439e4181328c213494b3d458c171473171
python3-ipaclient-4.9.8-11.el9_0.4.noarch.rpm SHA-256: 990be8fc1cc1864a2ac020fce03bd83f962f5a722c118bcac9df8e7fa6077595
python3-ipalib-4.9.8-11.el9_0.4.noarch.rpm SHA-256: b7eaf18d6372fae65098f47e2a637f0177126971b7aa9652a06ed6fc3723d79d
python3-ipaserver-4.9.8-11.el9_0.4.noarch.rpm SHA-256: 51cbbe8bb03dcb70660893c674dcfc41ec85e78bf4787f4a22829705f0239f73

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0

SRPM
ipa-4.9.8-11.el9_0.4.src.rpm SHA-256: a5c110f51ccbe76b1e917baaf6d56b7d47a84fb64f274978c3764ba19292bb92
x86_64
ipa-client-4.9.8-11.el9_0.4.x86_64.rpm SHA-256: 1cd10a5bcf222034e61ed10cd2437b1a0b474fbf3c2e07dd099f6afadf3d65db
ipa-client-common-4.9.8-11.el9_0.4.noarch.rpm SHA-256: c21fc9da5ded0fd9cb4310f4e9d4f6c55a48765ce07af4f39ca66de8f15ea9d2
ipa-client-debuginfo-4.9.8-11.el9_0.4.x86_64.rpm SHA-256: d450ee78ddd2a9181700483b92b67e75ccb9a5c5b6e409a82791114ab5a9e46a
ipa-client-epn-4.9.8-11.el9_0.4.x86_64.rpm SHA-256: 2afed245e9ee5cdf442584e8cc8f50472e94ca09df0017be91e683990178832c
ipa-client-samba-4.9.8-11.el9_0.4.x86_64.rpm SHA-256: 4848166751deb16db624bea2b8c77392574ae18ce7bf1ff35edb9b4358fe6668
ipa-common-4.9.8-11.el9_0.4.noarch.rpm SHA-256: b848aff43e5ca55849d8a831512a2b4aea15256c6b0d3b9d9b26c87fb7004df8
ipa-debuginfo-4.9.8-11.el9_0.4.x86_64.rpm SHA-256: 22f231b66b3f901cab4e54218c585a4658f3411793dc0703c00b9f57fa3db436
ipa-debugsource-4.9.8-11.el9_0.4.x86_64.rpm SHA-256: a38c4777c9bec495426481f42e1b41ea470b551a8b89de3e0c54d955599f477a
ipa-selinux-4.9.8-11.el9_0.4.noarch.rpm SHA-256: 6bb639521a333d32e1639fb810907543025f14e59a96469858bf5bdfc36aaf14
ipa-server-4.9.8-11.el9_0.4.x86_64.rpm SHA-256: e5c80274eb9f51abaa989f06f924fcd36143072461ce8a929911686b6ce48d75
ipa-server-common-4.9.8-11.el9_0.4.noarch.rpm SHA-256: fdcdd1a7b2a3bb34ce50efd0cc684bff72cdffbabd1749877c4d33c192dd694c
ipa-server-debuginfo-4.9.8-11.el9_0.4.x86_64.rpm SHA-256: 39eca9b734122e298d3ab47071bdfadc30e828cea14164e6a705738033d0f235
ipa-server-dns-4.9.8-11.el9_0.4.noarch.rpm SHA-256: 92d4df95a6598dc3b5eb1c0adaf421634c8a4b24f21bf146e8c07f780046531e
ipa-server-trust-ad-4.9.8-11.el9_0.4.x86_64.rpm SHA-256: f56ae3a4ae767f0670bf9f9b8c20b5e856fe19d93c73e745a50a9084ed6145b6
ipa-server-trust-ad-debuginfo-4.9.8-11.el9_0.4.x86_64.rpm SHA-256: bdf87c0a3fa46962cfe167ed5516d9398c7b6c1a2fc30505c7de9ea0a2599448
python3-ipaclient-4.9.8-11.el9_0.4.noarch.rpm SHA-256: 990be8fc1cc1864a2ac020fce03bd83f962f5a722c118bcac9df8e7fa6077595
python3-ipalib-4.9.8-11.el9_0.4.noarch.rpm SHA-256: b7eaf18d6372fae65098f47e2a637f0177126971b7aa9652a06ed6fc3723d79d
python3-ipaserver-4.9.8-11.el9_0.4.noarch.rpm SHA-256: 51cbbe8bb03dcb70660893c674dcfc41ec85e78bf4787f4a22829705f0239f73

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.0

SRPM
ipa-4.9.8-11.el9_0.4.src.rpm SHA-256: a5c110f51ccbe76b1e917baaf6d56b7d47a84fb64f274978c3764ba19292bb92
aarch64
ipa-client-4.9.8-11.el9_0.4.aarch64.rpm SHA-256: 14d1e786483e02a69293a145b442eb88001bbd85046e7acd1dfcfd9941fa7af6
ipa-client-common-4.9.8-11.el9_0.4.noarch.rpm SHA-256: c21fc9da5ded0fd9cb4310f4e9d4f6c55a48765ce07af4f39ca66de8f15ea9d2
ipa-client-debuginfo-4.9.8-11.el9_0.4.aarch64.rpm SHA-256: 999c62f58f7551aac0dbadea1f0d967589d1c73e6f388ae0e7109114e7455c35
ipa-client-epn-4.9.8-11.el9_0.4.aarch64.rpm SHA-256: 1b12fedff09a6713fd9a7379578d5cbfb11aee36c0021e27d7f93216d2117883
ipa-client-samba-4.9.8-11.el9_0.4.aarch64.rpm SHA-256: 4ff15386ed4734e8f2d1899d18a7331e476cf5a3793567ffb0b81451e020ca5c
ipa-common-4.9.8-11.el9_0.4.noarch.rpm SHA-256: b848aff43e5ca55849d8a831512a2b4aea15256c6b0d3b9d9b26c87fb7004df8
ipa-debuginfo-4.9.8-11.el9_0.4.aarch64.rpm SHA-256: 47e56db4336e4cd3f8763058eecf05dc4be84f5036dbd50e021e0d50fbed8b87
ipa-debugsource-4.9.8-11.el9_0.4.aarch64.rpm SHA-256: 2d16b53c49564e8d2d2064b4169cd5644705acac646c49dbcefcb1dc7b293d9e
ipa-selinux-4.9.8-11.el9_0.4.noarch.rpm SHA-256: 6bb639521a333d32e1639fb810907543025f14e59a96469858bf5bdfc36aaf14
ipa-server-4.9.8-11.el9_0.4.aarch64.rpm SHA-256: bb603d8ceb12fd398bec8e27f45096b7f7c671130f5dd9a183e15de6c52864aa
ipa-server-common-4.9.8-11.el9_0.4.noarch.rpm SHA-256: fdcdd1a7b2a3bb34ce50efd0cc684bff72cdffbabd1749877c4d33c192dd694c
ipa-server-debuginfo-4.9.8-11.el9_0.4.aarch64.rpm SHA-256: 416cd1632dddd3c295005685fa8f8393505356c6705e700407b43c687060d3ae
ipa-server-dns-4.9.8-11.el9_0.4.noarch.rpm SHA-256: 92d4df95a6598dc3b5eb1c0adaf421634c8a4b24f21bf146e8c07f780046531e
ipa-server-trust-ad-4.9.8-11.el9_0.4.aarch64.rpm SHA-256: f3951e6af5badb1d437b88037c2bd4a114b5a909d46e5cb32b087858d2b56d6d
ipa-server-trust-ad-debuginfo-4.9.8-11.el9_0.4.aarch64.rpm SHA-256: 50a375632185e08a72016921a5a58713a00925f24d71bbe2fb024589b239a065
python3-ipaclient-4.9.8-11.el9_0.4.noarch.rpm SHA-256: 990be8fc1cc1864a2ac020fce03bd83f962f5a722c118bcac9df8e7fa6077595
python3-ipalib-4.9.8-11.el9_0.4.noarch.rpm SHA-256: b7eaf18d6372fae65098f47e2a637f0177126971b7aa9652a06ed6fc3723d79d
python3-ipaserver-4.9.8-11.el9_0.4.noarch.rpm SHA-256: 51cbbe8bb03dcb70660893c674dcfc41ec85e78bf4787f4a22829705f0239f73

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.0

SRPM
ipa-4.9.8-11.el9_0.4.src.rpm SHA-256: a5c110f51ccbe76b1e917baaf6d56b7d47a84fb64f274978c3764ba19292bb92
s390x
ipa-client-4.9.8-11.el9_0.4.s390x.rpm SHA-256: 6defa503274a6a59a69746ffac9a46cf64d2d8a091b8b1c091a9b0c5393fb7a5
ipa-client-common-4.9.8-11.el9_0.4.noarch.rpm SHA-256: c21fc9da5ded0fd9cb4310f4e9d4f6c55a48765ce07af4f39ca66de8f15ea9d2
ipa-client-debuginfo-4.9.8-11.el9_0.4.s390x.rpm SHA-256: ae240faabaec53c8d9e852cb2d484491ba81b5cdf3287bf2cc156d375f6f7447
ipa-client-epn-4.9.8-11.el9_0.4.s390x.rpm SHA-256: 62551cedc73b220a282cdb1e879fb774741c163167a85085eef55ef048e13ddf
ipa-client-samba-4.9.8-11.el9_0.4.s390x.rpm SHA-256: a3d2631e388bafadc0e3dd263545f3b498220589635feb9caf13330e6981fd4f
ipa-common-4.9.8-11.el9_0.4.noarch.rpm SHA-256: b848aff43e5ca55849d8a831512a2b4aea15256c6b0d3b9d9b26c87fb7004df8
ipa-debuginfo-4.9.8-11.el9_0.4.s390x.rpm SHA-256: 63079ba7952266e438f6c0809e63136de1de7db9fa0c8faf6af64a8382bc6f7b
ipa-debugsource-4.9.8-11.el9_0.4.s390x.rpm SHA-256: 923f16529ac8a6a0d6b61c4366129bab1d9c99399a183d9f8b158911f28c2848
ipa-selinux-4.9.8-11.el9_0.4.noarch.rpm SHA-256: 6bb639521a333d32e1639fb810907543025f14e59a96469858bf5bdfc36aaf14
ipa-server-4.9.8-11.el9_0.4.s390x.rpm SHA-256: 92d88ec1ee8690fa1cab9e5b2b634b751d291a663eb5d4eccdc3a76d128b51d4
ipa-server-common-4.9.8-11.el9_0.4.noarch.rpm SHA-256: fdcdd1a7b2a3bb34ce50efd0cc684bff72cdffbabd1749877c4d33c192dd694c
ipa-server-debuginfo-4.9.8-11.el9_0.4.s390x.rpm SHA-256: f113f4ef6966ccf45479eba596e04c7e59ea518bb67b33db728e2737d9437c45
ipa-server-dns-4.9.8-11.el9_0.4.noarch.rpm SHA-256: 92d4df95a6598dc3b5eb1c0adaf421634c8a4b24f21bf146e8c07f780046531e
ipa-server-trust-ad-4.9.8-11.el9_0.4.s390x.rpm SHA-256: dab27b7f771d61513958da30c64ac2bea7e58336b74e68b0ba5ec47fe3a949fb
ipa-server-trust-ad-debuginfo-4.9.8-11.el9_0.4.s390x.rpm SHA-256: eb22277de8f4390f3e466bd0f3604169f44c15adebc104759ee74d3c11e0b565
python3-ipaclient-4.9.8-11.el9_0.4.noarch.rpm SHA-256: 990be8fc1cc1864a2ac020fce03bd83f962f5a722c118bcac9df8e7fa6077595
python3-ipalib-4.9.8-11.el9_0.4.noarch.rpm SHA-256: b7eaf18d6372fae65098f47e2a637f0177126971b7aa9652a06ed6fc3723d79d
python3-ipaserver-4.9.8-11.el9_0.4.noarch.rpm SHA-256: 51cbbe8bb03dcb70660893c674dcfc41ec85e78bf4787f4a22829705f0239f73

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility