[El-errata] ELSA-2026-70564 Critical: Oracle Linux 9 ipa security, bug fix, and enhancement update

Errata Announcements for Oracle Linux el-errata at oss.oracle.com
Fri Sep 25 13:36:04 UTC 2026


Oracle Linux Security Advisory ELSA-2026-70564

http://linux.oracle.com/errata/ELSA-2026-70564.html

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

x86_64:
ipa-client-4.13.4-1.0.1.el9_8.x86_64.rpm
ipa-client-common-4.13.4-1.0.1.el9_8.noarch.rpm
ipa-client-encrypted-dns-4.13.4-1.0.1.el9_8.x86_64.rpm
ipa-client-epn-4.13.4-1.0.1.el9_8.x86_64.rpm
ipa-client-samba-4.13.4-1.0.1.el9_8.x86_64.rpm
ipa-common-4.13.4-1.0.1.el9_8.noarch.rpm
ipa-selinux-4.13.4-1.0.1.el9_8.noarch.rpm
ipa-selinux-luna-4.13.4-1.0.1.el9_8.noarch.rpm
ipa-selinux-nfast-4.13.4-1.0.1.el9_8.noarch.rpm
ipa-server-4.13.4-1.0.1.el9_8.x86_64.rpm
ipa-server-common-4.13.4-1.0.1.el9_8.noarch.rpm
ipa-server-dns-4.13.4-1.0.1.el9_8.noarch.rpm
ipa-server-encrypted-dns-4.13.4-1.0.1.el9_8.x86_64.rpm
ipa-server-trust-ad-4.13.4-1.0.1.el9_8.x86_64.rpm
python3-ipaclient-4.13.4-1.0.1.el9_8.noarch.rpm
python3-ipalib-4.13.4-1.0.1.el9_8.noarch.rpm
python3-ipaserver-4.13.4-1.0.1.el9_8.noarch.rpm
python3-ipatests-4.13.4-1.0.1.el9_8.noarch.rpm

aarch64:
ipa-client-4.13.4-1.0.1.el9_8.aarch64.rpm
ipa-client-common-4.13.4-1.0.1.el9_8.noarch.rpm
ipa-client-encrypted-dns-4.13.4-1.0.1.el9_8.aarch64.rpm
ipa-client-epn-4.13.4-1.0.1.el9_8.aarch64.rpm
ipa-client-samba-4.13.4-1.0.1.el9_8.aarch64.rpm
ipa-common-4.13.4-1.0.1.el9_8.noarch.rpm
ipa-selinux-4.13.4-1.0.1.el9_8.noarch.rpm
ipa-selinux-luna-4.13.4-1.0.1.el9_8.noarch.rpm
ipa-selinux-nfast-4.13.4-1.0.1.el9_8.noarch.rpm
ipa-server-4.13.4-1.0.1.el9_8.aarch64.rpm
ipa-server-common-4.13.4-1.0.1.el9_8.noarch.rpm
ipa-server-dns-4.13.4-1.0.1.el9_8.noarch.rpm
ipa-server-encrypted-dns-4.13.4-1.0.1.el9_8.aarch64.rpm
ipa-server-trust-ad-4.13.4-1.0.1.el9_8.aarch64.rpm
python3-ipaclient-4.13.4-1.0.1.el9_8.noarch.rpm
python3-ipalib-4.13.4-1.0.1.el9_8.noarch.rpm
python3-ipaserver-4.13.4-1.0.1.el9_8.noarch.rpm
python3-ipatests-4.13.4-1.0.1.el9_8.noarch.rpm


SRPMS:
http://oss.oracle.com/ol9/SRPMS-updates/ipa-4.13.4-1.0.1.el9_8.src.rpm

Related CVEs:

CVE-2026-11861
CVE-2026-13097
CVE-2026-18147
CVE-2026-19550
CVE-2026-73197
CVE-2026-73198
CVE-2026-76578
CVE-2026-79678




Description of changes:

[4.13.4-1.0.1]
- Set IPAPLATFORM=rhel when build on Oracle Linux [Orabug: 29516674]
- Add bind to ipa-server-common Requires [Orabug: 36518596]

[4.13.4-1]
- RHEL-218866 CVE-2026-18147 ipa: FreeIPA/IdM: Cross-Site Scripting vulnerability allows arbitrary code execution via crafted URL [rhel-9.8.z]
- RHEL-245474 CVE-2026-76578 ipa: FreeIPA: unauthenticated LDAP client can obtain administrator credentials via the self-managed-token ACI [rhel-9.8.z]
- RHEL-248206 CVE-2026-79678 ipa: freeipa: idp-add eval() reachable before authorization check allows environment disclosure and denial of service [rhel-9.8.z]
- RHEL-245627 CVE-2026-19550 ipa: FreeIPA: trust-fetch-domains uses trust-read ACI to gate a privileged AD trust refresh, allowing unauthorized LDAP writes [rhel-9.8.z]
- RHEL-240898 CVE-2026-13097 ipa: Privilege escalation via krbCanonicalName manipulation due to realm-unaware uniqueness enforcement in FreeIPA LDAP datastore [rhel-9.8.z]
- RHEL-240830 CVE-2026-11861 ipa: FreeIPA: Obtaining TGS with impersonating cname through trust relationships [rhel-9.8.z]
- RHEL-240815 CVE-2026-73197 ipa: FreeIPA: Unauthenticated DoS in /ipa/migration/migration.py via Unbounded Request Body Read [rhel-9.8.z]
- RHEL-240804 CVE-2026-73198 ipa: FreeIPA: Unauthenticated DoS in /ipa/i18n_messages via Unbounded Request Body Read [rhel-9.8.z]
- RHEL-240767 ipa-migrate tool is renaming host records & host info in automount information [rhel-9.8.z]
- RHEL-238677 ipa-migrate: require Replication Administrator privilege [rhel-9.8.z]
- RHEL-238674 ipa-epn: drop_privileges method is mixing uid and gid [rhel-9.8.z]
- RHEL-238527 ipa env: support only simple * wildcard [rhel-9.8.z]

[4.13.1-3.2]
- Related: RHEL-166865 Include latest fixes in python3-ipatests package [rhel-9.8.z]

[4.13.1-3.1]
- Resolves: RHEL-166865 Include latest fixes in python3-ipatests package [rhel-9.8.z]
- Resolves: RHEL-155037 Pagure #9953: Adding a group with 32Bit Idrange fails. [rhel-9.8.z]
- Resolves: RHEL-153146 IdM password policy Min lifetime is not enforced when high minlife is set [rhel-9.8.z]
- Resolves: RHEL-168047 ipa ca-show ipa --all failing to list RSN version




More information about the El-errata mailing list