UBUNTU-CVE-2025-4404

Source
https://ubuntu.com/security/CVE-2025-4404
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-4404.json
JSON Data
https://api.test.osv.dev/v1/vulns/UBUNTU-CVE-2025-4404
Upstream
Published
2025-06-17T14:15:00Z
Modified
2025-07-14T07:02:39.399192Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

A privilege escalation from host to domain vulnerability was found in the FreeIPA project. The FreeIPA package fails to validate the uniqueness of the krbCanonicalName for the admin account by default, allowing users to create services with the same canonical name as the REALM admin. When a successful attack happens, the user can retrieve a Kerberos ticket in the name of this service, containing the admin@REALM credential. This flaw allows an attacker to perform administrative tasks over the REALM, leading to access to sensitive data and sensitive data exfiltration.

References

Affected packages

Ubuntu:Pro:14.04:LTS / freeipa

Package

Name
freeipa
Purl
pkg:deb/ubuntu/freeipa@3.3.4-0ubuntu3.1+esm1?arch=source&distro=esm-infra-legacy/trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*

3.2.1-0ubuntu1
3.3.4-0ubuntu1
3.3.4-0ubuntu2
3.3.4-0ubuntu3
3.3.4-0ubuntu3.1
3.3.4-0ubuntu3.1+esm1

Ubuntu:Pro:16.04:LTS / freeipa

Package

Name
freeipa
Purl
pkg:deb/ubuntu/freeipa@4.3.1-0ubuntu1+esm1?arch=source&distro=esm-apps/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4.*

4.1.4-1
4.3.1-0ubuntu1
4.3.1-0ubuntu1+esm1

Ubuntu:Pro:18.04:LTS / freeipa

Package

Name
freeipa
Purl
pkg:deb/ubuntu/freeipa@4.7.0~pre1+git20180411-2ubuntu2?arch=source&distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4.*

4.4.4-3ubuntu1
4.4.4-4
4.7.0~pre1+git20180411-2ubuntu1
4.7.0~pre1+git20180411-2ubuntu2

Ubuntu:Pro:20.04:LTS / freeipa

Package

Name
freeipa
Purl
pkg:deb/ubuntu/freeipa@4.8.6-1ubuntu2?arch=source&distro=esm-apps/focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4.*

4.8.1-2ubuntu1
4.8.3-1
4.8.6-1ubuntu2

Ubuntu:22.04:LTS / freeipa

Package

Name
freeipa
Purl
pkg:deb/ubuntu/freeipa@4.9.8-1?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4.*

4.8.6-1ubuntu6
4.8.6-1ubuntu8
4.8.6-1ubuntu9
4.9.8-1

Ubuntu:24.04:LTS / freeipa

Package

Name
freeipa
Purl
pkg:deb/ubuntu/freeipa@4.11.1-2?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4.*

4.10.2-1
4.10.2-2
4.10.2-2ubuntu3
4.11.1-1
4.11.1-2

Ubuntu:25.04 / freeipa

Package

Name
freeipa
Purl
pkg:deb/ubuntu/freeipa@4.12.2-3?arch=source&distro=plucky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4.*

4.11.1-2.1
4.12.2-1
4.12.2-2
4.12.2-3