REDHAT-BUG-2389448: High severity Red Hat FreeIPA vulnerability
Although CVE-2025-4404 fixed the lack of verification for the uniqueness of the LDAP attribute krbCanonicalName in FreeIPA, it doesn't prevent to achieve the same privilege escalation by using the the root kbrcanonicalname.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2389448?
The severity of REDHAT-BUG-2389448 is considered high due to the potential for privilege escalation.
How do I fix REDHAT-BUG-2389448?
To fix REDHAT-BUG-2389448, users should update to the latest version of Red Hat FreeIPA that addresses this vulnerability.
What does REDHAT-BUG-2389448 affect?
REDHAT-BUG-2389448 affects Red Hat FreeIPA, which is vulnerable due to improper handling of the root krbCanonicalName LDAP attribute.
Can REDHAT-BUG-2389448 be exploited remotely?
Yes, REDHAT-BUG-2389448 can potentially be exploited remotely by attackers able to interact with the FreeIPA server.
Is there a workaround for REDHAT-BUG-2389448?
Currently, there are no known workarounds for REDHAT-BUG-2389448, so applying the recommended updates is advised.