ALSA-2025:21140

Source
https://errata.almalinux.org/8/ALSA-2025-21140.html
Import Source
https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2025:21140.json
JSON Data
https://api.test.osv.dev/v1/vulns/ALSA-2025:21140
Related
  • CVE-2025-59088
  • CVE-2025-59089
Published
2025-11-12T00:00:00Z
Modified
2025-11-20T14:30:20.445439Z
Summary
Important: idm:DL1 security update
Details

AlmaLinux Identity Management (IdM) is a centralized authentication, identity management, and authorization solution for both traditional and cloud-based enterprise environments.

Security Fix(es):

  • python-kdcproxy: Unauthenticated SSRF via Realm?Controlled DNS SRV (CVE-2025-59088)
  • python-kdcproxy: Remote DoS via unbounded TCP upstream buffering (CVE-2025-59089)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

References

Affected packages

AlmaLinux:8

bind-dyndb-ldap

Package

Name
bind-dyndb-ldap
Purl
pkg:rpm/almalinux/bind-dyndb-ldap

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
11.6-6.module_el8.10.0+3980+d78e8e90

custodia

Package

Name
custodia
Purl
pkg:rpm/almalinux/custodia

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.6.0-3.module_el8.6.0+2881+2f24dc92

ipa-client

Package

Name
ipa-client
Purl
pkg:rpm/almalinux/ipa-client

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.9.13-20.module_el8.10.0+4050+3b475c71

ipa-client-common

Package

Name
ipa-client-common
Purl
pkg:rpm/almalinux/ipa-client-common

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.9.13-20.module_el8.10.0+4050+3b475c71

ipa-client-epn

Package

Name
ipa-client-epn
Purl
pkg:rpm/almalinux/ipa-client-epn

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.9.13-20.module_el8.10.0+4050+3b475c71

ipa-client-samba

Package

Name
ipa-client-samba
Purl
pkg:rpm/almalinux/ipa-client-samba

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.9.13-20.module_el8.10.0+4050+3b475c71

ipa-common

Package

Name
ipa-common
Purl
pkg:rpm/almalinux/ipa-common

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.9.13-20.module_el8.10.0+4050+3b475c71

ipa-healthcheck

Package

Name
ipa-healthcheck
Purl
pkg:rpm/almalinux/ipa-healthcheck

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.12-6.module_el8.10.0+4036+84b152d9

ipa-healthcheck-core

Package

Name
ipa-healthcheck-core
Purl
pkg:rpm/almalinux/ipa-healthcheck-core

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.12-6.module_el8.10.0+4036+84b152d9

ipa-python-compat

Package

Name
ipa-python-compat
Purl
pkg:rpm/almalinux/ipa-python-compat

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.9.13-20.module_el8.10.0+4050+3b475c71

ipa-selinux

Package

Name
ipa-selinux
Purl
pkg:rpm/almalinux/ipa-selinux

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.9.13-20.module_el8.10.0+4050+3b475c71

ipa-server

Package

Name
ipa-server
Purl
pkg:rpm/almalinux/ipa-server

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.9.13-20.module_el8.10.0+4050+3b475c71

ipa-server-common

Package

Name
ipa-server-common
Purl
pkg:rpm/almalinux/ipa-server-common

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.9.13-20.module_el8.10.0+4050+3b475c71

ipa-server-dns

Package

Name
ipa-server-dns
Purl
pkg:rpm/almalinux/ipa-server-dns

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.9.13-20.module_el8.10.0+4050+3b475c71

ipa-server-trust-ad

Package

Name
ipa-server-trust-ad
Purl
pkg:rpm/almalinux/ipa-server-trust-ad

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.9.13-20.module_el8.10.0+4050+3b475c71

opendnssec

Package

Name
opendnssec
Purl
pkg:rpm/almalinux/opendnssec

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.1.7-2.module_el8.10.0+3980+d78e8e90

python3-custodia

Package

Name
python3-custodia
Purl
pkg:rpm/almalinux/python3-custodia

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.6.0-3.module_el8.6.0+2881+2f24dc92

python3-ipaclient

Package

Name
python3-ipaclient
Purl
pkg:rpm/almalinux/python3-ipaclient

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.9.13-20.module_el8.10.0+4050+3b475c71

python3-ipalib

Package

Name
python3-ipalib
Purl
pkg:rpm/almalinux/python3-ipalib

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.9.13-20.module_el8.10.0+4050+3b475c71

python3-ipaserver

Package

Name
python3-ipaserver
Purl
pkg:rpm/almalinux/python3-ipaserver

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.9.13-20.module_el8.10.0+4050+3b475c71

python3-ipatests

Package

Name
python3-ipatests
Purl
pkg:rpm/almalinux/python3-ipatests

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.9.13-20.module_el8.10.0+4050+3b475c71

python3-jwcrypto

Package

Name
python3-jwcrypto
Purl
pkg:rpm/almalinux/python3-jwcrypto

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.5.0-2.module_el8.10.0+3844+20e075e5

python3-kdcproxy

Package

Name
python3-kdcproxy
Purl
pkg:rpm/almalinux/python3-kdcproxy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.4-5.module_el8.10.0+4069+1d9eaa78.2

python3-pyusb

Package

Name
python3-pyusb
Purl
pkg:rpm/almalinux/python3-pyusb

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0.0-9.1.module_el8.7.0+3349+cfeff52e

python3-qrcode

Package

Name
python3-qrcode
Purl
pkg:rpm/almalinux/python3-qrcode

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.3-1.module_el8.10.0+3942+63b39a46

python3-qrcode-core

Package

Name
python3-qrcode-core
Purl
pkg:rpm/almalinux/python3-qrcode-core

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.3-1.module_el8.10.0+3942+63b39a46

python3-yubico

Package

Name
python3-yubico
Purl
pkg:rpm/almalinux/python3-yubico

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.3.2-9.1.module_el8.7.0+3349+cfeff52e

slapi-nis

Package

Name
slapi-nis
Purl
pkg:rpm/almalinux/slapi-nis

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.60.0-4.module_el8.10.0+3844+20e075e5.alma.1

softhsm

Package

Name
softhsm
Purl
pkg:rpm/almalinux/softhsm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.6.0-5.module_el8.6.0+2881+2f24dc92

softhsm

Package

Name
softhsm
Purl
pkg:rpm/almalinux/softhsm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.6.0-5.module_el8.6.0+3031+2f24dc92

softhsm-devel

Package

Name
softhsm-devel
Purl
pkg:rpm/almalinux/softhsm-devel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.6.0-5.module_el8.6.0+2881+2f24dc92

softhsm-devel

Package

Name
softhsm-devel
Purl
pkg:rpm/almalinux/softhsm-devel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.6.0-5.module_el8.6.0+3031+2f24dc92