Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Update to Samba 4.23.8 - Security fix for CVE-2026-4480, CVE-2026-2340, CVE-2026-3012, CVE-2026-1933, CVE-2026-4408, and CVE-2026-3238. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-fc81581a79 2026-06-05 04:07:33.980053+00:00 -------------------------------------------------------------------------------- Name : freeipa Product : Fedora 43 Version : 4.13.1 Release : 7.fc43 URL : http://www.freeipa.org/ Summary : The Identity, Policy and Audit system Description : IPA is an integrated solution to provide centrally managed Identity (users, hosts, services), Authentication (SSO, 2FA), and Authorization (host access control, SELinux user roles, services). The solution provides features for further integration with Linux based clients (SUDO, automount) and integration with Active Directory based infrastructures (Trusts). -------------------------------------------------------------------------------- Update Information: Update to Samba 4.23.8 - Security fix for CVE-2026-4480, CVE-2026-2340, CVE-2026-3012, CVE-2026-1933, CVE-2026-4408, and CVE-2026-3238 -------------------------------------------------------------------------------- ChangeLog: * Fri May 29 2026 Alexander Bokovoy - 4.13.1-7 - Rebuild against Samba 4.23.8 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2481447 - CVE-2026-4480 samba: Samba: Remote Code Execution in printing subsystem via unescaped job description [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2481447 [ 2 ] Bug #2481857 - CVE-2026-3012 samba: group policy certificate enrollment uses http:// without validation [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2481857 [ 3 ] Bug #2481875 - CVE-2026-2340 samba: vfs_worm does not block directory modification [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2481875 [ 4 ] Bug #2481876- CVE-2026-1933 samba: Missing access check on reparse point operations [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2481876 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-fc81581a79' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Important: idm:DL1 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2025:21140", "synopsis": "Important: idm:DL1 security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for ipa-healthcheck, module.softhsm, bind-dyndb-ldap, module.ipa-healthcheck, python-yubico, python-jwcrypto, custodia, opendnssec, module.python-qrcode, module.python-kdcproxy, slapi-nis, module.python-yubico, module.python-jwcrypto, softhsm, module.ipa, module.slapi-nis, module.bind-dyndb-ldap, python-kdcproxy, module.opendnssec, ipa, python-qrcode, module.custodia, module.pyusb, pyusb.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Rocky Enterprise Software Foundation Identity Management (IdM) is a centralized authentication, identity management, and authorization solution for both traditional and cloud-based enterprise environments. \n\nSecurity Fix(es):\n\n* python-kdcproxy: Unauthenticated SSRF via Realm?Controlled DNS SRV (CVE-2025-59088)\n\n* python-kdcproxy: Remote DoS via unbounded TCP upstream buffering (CVE-2025-59089)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2393955", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2393955", "description": ""}, {"ticket": "2393958", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2393958", "description": ""}], "cves": [{"name": "CVE-2025-59088", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-59088", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N", "cvss3BaseScore": "8.6", "cwe": "CWE-918"}, {"name": "CVE-2025-59089", "sourceBy": "MITRE","sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-59089", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.9", "cwe": "CWE-770"}], "references": [], "publishedAt": "2025-11-27T09:05:18.620599Z", "rpms": {"Rocky Linux 8": {"nvras": ["bind-dyndb-ldap-0:11.6-6.module+el8.10.0+1960+1ed527b3.aarch64.rpm", "bind-dyndb-ldap-0:11.6-6.module+el8.10.0+1960+1ed527b3.src.rpm", "bind-dyndb-ldap-0:11.6-6.module+el8.10.0+1960+1ed527b3.x86_64.rpm", "bind-dyndb-ldap-debuginfo-0:11.6-6.module+el8.10.0+1960+1ed527b3.aarch64.rpm", "bind-dyndb-ldap-debuginfo-0:11.6-6.module+el8.10.0+1960+1ed527b3.x86_64.rpm", "bind-dyndb-ldap-debugsource-0:11.6-6.module+el8.10.0+1960+1ed527b3.aarch64.rpm", "bind-dyndb-ldap-debugsource-0:11.6-6.module+el8.10.0+1960+1ed527b3.x86_64.rpm", "custodia-0:0.6.0-3.module+el8.9.0+1371+ffa84eb9.noarch.rpm", "custodia-0:0.6.0-3.module+el8.9.0+1371+ffa84eb9.src.rpm", "ipa-0:4.9.13-20.module+el8.10.0+2067+377bdd64.src.rpm", "ipa-0:4.9.13-20.module+el8.10.0+2066+d74ade98.src.rpm", "ipa-client-0:4.9.13-20.module+el8.10.0+2066+d74ade98.aarch64.rpm", "ipa-client-0:4.9.13-20.module+el8.10.0+2067+377bdd64.aarch64.rpm", "ipa-client-0:4.9.13-20.module+el8.10.0+2066+d74ade98.x86_64.rpm", "ipa-client-0:4.9.13-20.module+el8.10.0+2067+377bdd64.x86_64.rpm", "ipa-client-common-0:4.9.13-20.module+el8.10.0+2067+377bdd64.noarch.rpm", "ipa-client-common-0:4.9.13-20.module+el8.10.0+2066+d74ade98.noarch.rpm", "ipa-client-debuginfo-0:4.9.13-20.module+el8.10.0+2066+d74ade98.aarch64.rpm", "ipa-client-debuginfo-0:4.9.13-20.module+el8.10.0+2067+377bdd64.aarch64.rpm", "ipa-client-debuginfo-0:4.9.13-20.module+el8.10.0+2067+377bdd64.x86_64.rpm", "ipa-client-debuginfo-0:4.9.13-20.module+el8.10.0+2066+d74ade98.x86_64.rpm", "ipa-client-epn-0:4.9.13-20.module+el8.10.0+2066+d74ade98.aarch64.rpm", "ipa-client-epn-0:4.9.13-20.module+el8.10.0+2067+377bdd64.aarch64.rpm", "ipa-client-epn-0:4.9.13-20.module+el8.10.0+2066+d74ade98.x86_64.rpm","ipa-client-epn-0:4.9.13-20.module+el8.10.0+2067+377bdd64.x86_64.rpm", "ipa-client-samba-0:4.9.13-20.module+el8.10.0+2067+377bdd64.aarch64.rpm", "ipa-client-samba-0:4.9.13-20.module+el8.10.0+2066+d74ade98.aarch64.rpm", "ipa-client-samba-0:4.9.13-20.module+el8.10.0+2067+377bdd64.x86_64.rpm", "ipa-client-samba-0:4.9.13-20.module+el8.10.0+2066+d74ade98.x86_64.rpm", "ipa-common-0:4.9.13-20.module+el8.10.0+2067+377bdd64.noarch.rpm", "ipa-common-0:4.9.13-20.module+el8.10.0+2066+d74ade98.noarch.rpm", "ipa-debuginfo-0:4.9.13-20.module+el8.10.0+2066+d74ade98.aarch64.rpm", "ipa-debuginfo-0:4.9.13-20.module+el8.10.0+2067+377bdd64.aarch64.rpm", "ipa-debuginfo-0:4.9.13-20.module+el8.10.0+2066+d74ade98.x86_64.rpm", "ipa-debuginfo-0:4.9.13-20.module+el8.10.0+2067+377bdd64.x86_64.rpm", "ipa-debugsource-0:4.9.13-20.module+el8.10.0+2067+377bdd64.aarch64.rpm", "ipa-debugsource-0:4.9.13-20.module+el8.10.0+2066+d74ade98.aarch64.rpm", "ipa-debugsource-0:4.9.13-20.module+el8.10.0+2066+d74ade98.x86_64.rpm", "ipa-debugsource-0:4.9.13-20.module+el8.10.0+2067+377bdd64.x86_64.rpm", "ipa-healthcheck-0:0.12-6.module+el8.10.0+2054+aa003774.noarch.rpm", "ipa-healthcheck-0:0.12-6.module+el8.10.0+2053+a0a9dc19.src.rpm", "ipa-healthcheck-0:0.12-6.module+el8.10.0+2054+aa003774.src.rpm", "ipa-healthcheck-core-0:0.12-6.module+el8.10.0+2054+aa003774.noarch.rpm", "ipa-healthcheck-core-0:0.12-6.module+el8.10.0+2053+a0a9dc19.noarch.rpm", "ipa-python-compat-0:4.9.13-20.module+el8.10.0+2067+377bdd64.noarch.rpm", "ipa-python-compat-0:4.9.13-20.module+el8.10.0+2066+d74ade98.noarch.rpm", "ipa-selinux-0:4.9.13-20.module+el8.10.0+2066+d74ade98.noarch.rpm", "ipa-selinux-0:4.9.13-20.module+el8.10.0+2067+377bdd64.noarch.rpm", "ipa-server-0:4.9.13-20.module+el8.10.0+2066+d74ade98.aarch64.rpm", "ipa-server-0:4.9.13-20.module+el8.10.0+2066+d74ade98.x86_64.rpm", "ipa-server-common-0:4.9.13-20.module+el8.10.0+2066+d74ade98.noarch.rpm", "ipa-server-debuginfo-0:4.9.13-20.module+el8.10.0+2066+d74ade98.aarch64.rpm","ipa-server-debuginfo-0:4.9.13-20.module+el8.10.0+2066+d74ade98.x86_64.rpm", "ipa-server-dns-0:4.9.13-20.module+el8.10.0+2066+d74ade98.noarch.rpm", "ipa-server-trust-ad-0:4.9.13-20.module+el8.10.0+2066+d74ade98.aarch64.rpm", "ipa-server-trust-ad-0:4.9.13-20.module+el8.10.0+2066+d74ade98.x86_64.rpm", "ipa-server-trust-ad-debuginfo-0:4.9.13-20.module+el8.10.0+2066+d74ade98.aarch64.rpm", "ipa-server-trust-ad-debuginfo-0:4.9.13-20.module+el8.10.0+2066+d74ade98.x86_64.rpm", "opendnssec-0:2.1.7-2.module+el8.10.0+1960+1ed527b3.aarch64.rpm", "opendnssec-0:2.1.7-2.module+el8.10.0+1960+1ed527b3.src.rpm", "opendnssec-0:2.1.7-2.module+el8.10.0+1960+1ed527b3.x86_64.rpm", "opendnssec-debuginfo-0:2.1.7-2.module+el8.10.0+1960+1ed527b3.aarch64.rpm", "opendnssec-debuginfo-0:2.1.7-2.module+el8.10.0+1960+1ed527b3.x86_64.rpm", "opendnssec-debugsource-0:2.1.7-2.module+el8.10.0+1960+1ed527b3.aarch64.rpm", "opendnssec-debugsource-0:2.1.7-2.module+el8.10.0+1960+1ed527b3.x86_64.rpm", "python3-custodia-0:0.6.0-3.module+el8.9.0+1371+ffa84eb9.noarch.rpm", "python3-ipaclient-0:4.9.13-20.module+el8.10.0+2066+d74ade98.noarch.rpm", "python3-ipaclient-0:4.9.13-20.module+el8.10.0+2067+377bdd64.noarch.rpm", "python3-ipalib-0:4.9.13-20.module+el8.10.0+2067+377bdd64.noarch.rpm", "python3-ipalib-0:4.9.13-20.module+el8.10.0+2066+d74ade98.noarch.rpm", "python3-ipaserver-0:4.9.13-20.module+el8.10.0+2066+d74ade98.noarch.rpm", "python3-ipatests-0:4.9.13-20.module+el8.10.0+2066+d74ade98.noarch.rpm", "python3-jwcrypto-0:0.5.0-2.module+el8.10.0+1819+0aeba2f1.noarch.rpm", "python3-jwcrypto-0:0.5.0-2.module+el8.10.0+1818+2dfda7a6.noarch.rpm", "python3-kdcproxy-0:0.4-5.module+el8.10.0+2094+d7886766.2.noarch.rpm", "python3-pyusb-0:1.0.0-9.1.module+el8.9.0+1372+09f67869.noarch.rpm", "python3-pyusb-0:1.0.0-9.1.module+el8.9.0+1371+ffa84eb9.noarch.rpm", "python3-qrcode-0:5.3-1.module+el8.10.0+1916+6bb8cf6b.noarch.rpm", "python3-qrcode-0:5.3-1.module+el8.10.0+1915+3c70f7d9.noarch.rpm", "python3-qrcode-core-0:5.3-1.module+el8.10.0+1916+6bb8cf6b.noarch.rpm","python3-qrcode-core-0:5.3-1.module+el8.10.0+1915+3c70f7d9.noarch.rpm", "python3-yubico-0:1.3.2-9.1.module+el8.9.0+1371+ffa84eb9.noarch.rpm", "python3-yubico-0:1.3.2-9.1.module+el8.9.0+1372+09f67869.noarch.rpm", "python-jwcrypto-0:0.5.0-2.module+el8.10.0+1818+2dfda7a6.src.rpm", "python-jwcrypto-0:0.5.0-2.module+el8.10.0+1819+0aeba2f1.src.rpm", "python-kdcproxy-0:0.4-5.module+el8.9.0+1371+ffa84eb9.src.rpm", "python-kdcproxy-0:0.4-5.module+el8.10.0+1915+3c70f7d9.1.src.rpm", "python-kdcproxy-0:0.4-5.module+el8.10.0+2094+d7886766.2.src.rpm", "python-qrcode-0:5.3-1.module+el8.10.0+1915+3c70f7d9.src.rpm", "python-qrcode-0:5.3-1.module+el8.10.0+1916+6bb8cf6b.src.rpm", "python-yubico-0:1.3.2-9.1.module+el8.9.0+1372+09f67869.src.rpm", "python-yubico-0:1.3.2-9.1.module+el8.9.0+1371+ffa84eb9.src.rpm", "pyusb-0:1.0.0-9.1.module+el8.9.0+1372+09f67869.src.rpm", "pyusb-0:1.0.0-9.1.module+el8.9.0+1371+ffa84eb9.src.rpm", "slapi-nis-0:0.60.0-4.module+el8.9.0+1573+39ab85f4.aarch64.rpm", "slapi-nis-0:0.60.0-4.module+el8.9.0+1573+39ab85f4.src.rpm", "slapi-nis-0:0.60.0-4.module+el8.9.0+1573+39ab85f4.x86_64.rpm", "slapi-nis-debuginfo-0:0.60.0-4.module+el8.9.0+1573+39ab85f4.aarch64.rpm", "slapi-nis-debuginfo-0:0.60.0-4.module+el8.9.0+1573+39ab85f4.x86_64.rpm", "slapi-nis-debugsource-0:0.60.0-4.module+el8.9.0+1573+39ab85f4.aarch64.rpm", "slapi-nis-debugsource-0:0.60.0-4.module+el8.9.0+1573+39ab85f4.x86_64.rpm", "softhsm-0:2.6.0-5.module+el8.9.0+1371+ffa84eb9.aarch64.rpm", "softhsm-0:2.6.0-5.module+el8.9.0+1371+ffa84eb9.src.rpm", "softhsm-0:2.6.0-5.module+el8.9.0+1371+ffa84eb9.x86_64.rpm", "softhsm-debuginfo-0:2.6.0-5.module+el8.9.0+1371+ffa84eb9.aarch64.rpm", "softhsm-debuginfo-0:2.6.0-5.module+el8.9.0+1371+ffa84eb9.x86_64.rpm", "softhsm-debugsource-0:2.6.0-5.module+el8.9.0+1371+ffa84eb9.aarch64.rpm", "softhsm-debugsource-0:2.6.0-5.module+el8.9.0+1371+ffa84eb9.x86_64.rpm", "softhsm-devel-0:2.6.0-5.module+el8.9.0+1371+ffa84eb9.aarch64.rpm", "softhsm-devel-0:2.6.0-5.module+el8.9.0+1371+ffa84eb9.x86_64.rpm","python3-kdcproxy-0:0.4-5.module+el8.10.0+1915+3c70f7d9.1.noarch.rpm", "python3-kdcproxy-0:0.4-5.module+el8.9.0+1371+ffa84eb9.noarch.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Rocky Linux 8 receives an important security update for idm affecting multiple applications with significant DoS risks.. Rocky Linux security updates DoS SSRF. . Severity: Important. LinuxSecurity.com Team
CVE-2024-11029 Release note: https://www.freeipa.org/release-notes/4-12-3.html. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-6baf694c75 2025-01-27 01:55:15.215313+00:00 -------------------------------------------------------------------------------- Name : freeipa Product : Fedora 40 Version : 4.12.2 Release : 3.fc40 URL : http://www.freeipa.org/ Summary : The Identity, Policy and Audit system Description : IPA is an integrated solution to provide centrally managed Identity (users, hosts, services), Authentication (SSO, 2FA), and Authorization (host access control, SELinux user roles, services). The solution provides features for further integration with Linux based clients (SUDO, automount) and integration with Active Directory based infrastructures (Trusts). -------------------------------------------------------------------------------- Update Information: CVE-2024-11029 Release note: https://www.freeipa.org/release-notes/4-12-3.html -------------------------------------------------------------------------------- ChangeLog: * Wed Jan 15 2025 Alexander Bokovoy - 4.12.2-3 - CVE-2024-11029 - Release notes: https://www.freeipa.org/release-notes/4-12-3.html -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-6baf694c75' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list
CVE-2024-11029 Release note: https://www.freeipa.org/release-notes/4-12-3.html. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-b21777d1b5 2025-01-27 01:38:38.335848+00:00 -------------------------------------------------------------------------------- Name : freeipa Product : Fedora 41 Version : 4.12.2 Release : 7.fc41 URL : http://www.freeipa.org/ Summary : The Identity, Policy and Audit system Description : IPA is an integrated solution to provide centrally managed Identity (users, hosts, services), Authentication (SSO, 2FA), and Authorization (host access control, SELinux user roles, services). The solution provides features for further integration with Linux based clients (SUDO, automount) and integration with Active Directory based infrastructures (Trusts). -------------------------------------------------------------------------------- Update Information: CVE-2024-11029 Release note: https://www.freeipa.org/release-notes/4-12-3.html -------------------------------------------------------------------------------- ChangeLog: * Wed Jan 15 2025 Alexander Bokovoy - 4.12.2-7 - CVE-2024-11029 - Release notes: https://www.freeipa.org/release-notes/4-12-3.html -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-b21777d1b5' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list
Fix CVE-2024-2698 and CVE-2024-3183. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-1d1b485611 2024-06-29 01:41:49.505912 -------------------------------------------------------------------------------- Name : freeipa Product : Fedora 39 Version : 4.12.1 Release : 1.fc39 URL : http://www.freeipa.org/ Summary : The Identity, Policy and Audit system Description : IPA is an integrated solution to provide centrally managed Identity (users, hosts, services), Authentication (SSO, 2FA), and Authorization (host access control, SELinux user roles, services). The solution provides features for further integration with Linux based clients (SUDO, automount) and integration with Active Directory based infrastructures (Trusts). -------------------------------------------------------------------------------- Update Information: Fix CVE-2024-2698 and CVE-2024-3183 -------------------------------------------------------------------------------- ChangeLog: * Tue Jun 11 2024 Julien Rische - 4.12.1-1 - Upstream release 4.12.1 - Release notes: https://www.freeipa.org/release-notes/4-12-1.html - Security release: CVE-2024-2698 CVE-2024-3183 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2291164 - CVE-2024-3183 freeipa: user can obtain a hash of the passwords of all domain users and perform offline brute force [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2291164 [ 2 ] Bug #2291165 - CVE-2024-2698 freeipa: delegation rules allow a proxy service to impersonate any user to access another target service [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2291165 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-1d1b485611' at the command line. For moreinformation, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Fix CVE-2024-2698 and CVE-2024-3183. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-2a466c6514 2024-06-27 02:02:42.637986 -------------------------------------------------------------------------------- Name : freeipa Product : Fedora 40 Version : 4.12.1 Release : 1.fc40 URL : http://www.freeipa.org/ Summary : The Identity, Policy and Audit system Description : IPA is an integrated solution to provide centrally managed Identity (users, hosts, services), Authentication (SSO, 2FA), and Authorization (host access control, SELinux user roles, services). The solution provides features for further integration with Linux based clients (SUDO, automount) and integration with Active Directory based infrastructures (Trusts). -------------------------------------------------------------------------------- Update Information: Fix CVE-2024-2698 and CVE-2024-3183 -------------------------------------------------------------------------------- ChangeLog: * Tue Jun 11 2024 Julien Rische - 4.12.1-1 - Upstream release 4.12.1 - Release notes: https://www.freeipa.org/release-notes/4-12-1.html - Security release: CVE-2024-2698 CVE-2024-3183 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2291164 - CVE-2024-3183 freeipa: user can obtain a hash of the passwords of all domain users and perform offline brute force [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2291164 [ 2 ] Bug #2291165 - CVE-2024-2698 freeipa: delegation rules allow a proxy service to impersonate any user to access another target service [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2291165 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-2a466c6514' at the command line. For moreinformation, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Important: ipa security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2024:3754", "synopsis": "Important: ipa security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for ipa.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Rocky Enterprise Software Foundation Identity Management (IdM) is a centralized authentication, identity management, and authorization solution for both traditional and cloud-based enterprise environments.\n\nSecurity Fix(es):\n\n* freeipa: delegation rules allow a proxy service to impersonate any user to access another target service (CVE-2024-2698)\n\n* freeipa: user can obtain a hash of the passwords of all domain users and perform offline brute force (CVE-2024-3183)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2270353", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2270353", "description": ""}, {"ticket": "2270685", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2270685", "description": ""}], "cves": [{"name": "CVE-2024-2698", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-2698", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2024-3183", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-3183", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}], "references": [], "publishedAt": "2024-06-14T14:00:35.848917Z", "rpms": {"Rocky Linux 9": {"nvras": ["ipa-0:4.11.0-15.el9_4.src.rpm", "ipa-client-0:4.11.0-15.el9_4.aarch64.rpm","ipa-client-0:4.11.0-15.el9_4.ppc64le.rpm", "ipa-client-0:4.11.0-15.el9_4.s390x.rpm", "ipa-client-0:4.11.0-15.el9_4.x86_64.rpm", "ipa-client-common-0:4.11.0-15.el9_4.noarch.rpm", "ipa-client-debuginfo-0:4.11.0-15.el9_4.aarch64.rpm", "ipa-client-debuginfo-0:4.11.0-15.el9_4.ppc64le.rpm", "ipa-client-debuginfo-0:4.11.0-15.el9_4.s390x.rpm", "ipa-client-debuginfo-0:4.11.0-15.el9_4.x86_64.rpm", "ipa-client-epn-0:4.11.0-15.el9_4.aarch64.rpm", "ipa-client-epn-0:4.11.0-15.el9_4.ppc64le.rpm", "ipa-client-epn-0:4.11.0-15.el9_4.s390x.rpm", "ipa-client-epn-0:4.11.0-15.el9_4.x86_64.rpm", "ipa-client-samba-0:4.11.0-15.el9_4.aarch64.rpm", "ipa-client-samba-0:4.11.0-15.el9_4.ppc64le.rpm", "ipa-client-samba-0:4.11.0-15.el9_4.s390x.rpm", "ipa-client-samba-0:4.11.0-15.el9_4.x86_64.rpm", "ipa-common-0:4.11.0-15.el9_4.noarch.rpm", "ipa-selinux-0:4.11.0-15.el9_4.noarch.rpm", "ipa-server-0:4.11.0-15.el9_4.aarch64.rpm", "ipa-server-0:4.11.0-15.el9_4.ppc64le.rpm", "ipa-server-0:4.11.0-15.el9_4.s390x.rpm", "ipa-server-0:4.11.0-15.el9_4.x86_64.rpm", "ipa-server-common-0:4.11.0-15.el9_4.noarch.rpm", "ipa-server-debuginfo-0:4.11.0-15.el9_4.aarch64.rpm", "ipa-server-debuginfo-0:4.11.0-15.el9_4.ppc64le.rpm", "ipa-server-debuginfo-0:4.11.0-15.el9_4.s390x.rpm", "ipa-server-debuginfo-0:4.11.0-15.el9_4.x86_64.rpm", "ipa-server-dns-0:4.11.0-15.el9_4.noarch.rpm", "ipa-server-trust-ad-0:4.11.0-15.el9_4.aarch64.rpm", "ipa-server-trust-ad-0:4.11.0-15.el9_4.ppc64le.rpm", "ipa-server-trust-ad-0:4.11.0-15.el9_4.s390x.rpm", "ipa-server-trust-ad-0:4.11.0-15.el9_4.x86_64.rpm", "ipa-server-trust-ad-debuginfo-0:4.11.0-15.el9_4.aarch64.rpm", "ipa-server-trust-ad-debuginfo-0:4.11.0-15.el9_4.ppc64le.rpm", "ipa-server-trust-ad-debuginfo-0:4.11.0-15.el9_4.s390x.rpm", "ipa-server-trust-ad-debuginfo-0:4.11.0-15.el9_4.x86_64.rpm", "python3-ipaclient-0:4.11.0-15.el9_4.noarch.rpm", "python3-ipalib-0:4.11.0-15.el9_4.noarch.rpm", "python3-ipaserver-0:4.11.0-15.el9_4.noarch.rpm", "python3-ipatests-0:4.11.0-15.el9_4.noarch.rpm"]}}, "rebootSuggested": false,"buildReferences": []}. The latest ipa patch from Rocky Linux tackles security flaws affecting identity verification and user access.. Rocky Linux Security Update, ipa Vulnerability Fix, Identity Management Improvements. . Severity: Important. LinuxSecurity.com Team
Upstream security release for CVE-2023-5455. Release notes: https://www.freeipa.org/release-notes/4-10-3.html. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-403145c4fb 2024-01-26 00:42:11.401778 -------------------------------------------------------------------------------- Name : freeipa Product : Fedora 38 Version : 4.10.3 Release : 1.fc38 URL : https://www.freeipa.org/ Summary : The Identity, Policy and Audit system Description : IPA is an integrated solution to provide centrally managed Identity (users, hosts, services), Authentication (SSO, 2FA), and Authorization (host access control, SELinux user roles, services). The solution provides features for further integration with Linux based clients (SUDO, automount) and integration with Active Directory based infrastructures (Trusts). -------------------------------------------------------------------------------- Update Information: Upstream security release for CVE-2023-5455. Release notes: https://www.freeipa.org/release-notes/4-10-3.html -------------------------------------------------------------------------------- ChangeLog: * Wed Jan 10 2024 Alexander Bokovoy - 4.10.3-1 - Security release: CVE-2023-5455 - Resolves: rhbz#2257646 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2257646 - CVE-2023-5455 freeipa: ipa: Invalid CSRF protection [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2257646 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-403145c4fb' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by theFedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.