ALAS2-2026-3877


Amazon Linux 2 Security Advisory: ALAS2-2026-3877
Advisory Released Date: 2026-08-25
Advisory Updated Date: 2026-08-25
Severity: Critical

Issue Overview:

A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Directory users can bypass authentication for FreeIPA services, including the portal, SMB server, and LDAP directory. This is possible by impersonating a client name in the Ticket Granting Service (TGS) due to FreeIPA services not verifying Privilege Attribute Certificate (PAC) certificates. This vulnerability could allow an authenticated Active Directory user to escalate their privileges within the FreeIPA domain. (CVE-2026-11861)

A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory server does not properly account for equivalent representations of the same principal name, allowing a user with sufficient LDAP write privileges to create a service principal that impersonates an existing privileged one. This can lead to unauthorized acquisition of Kerberos service tickets for sensitive services, potentially resulting in full domain compromise. (CVE-2026-13097)


Affected Packages:

ipa


Note:

This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.


Issue Correction:
Run yum update ipa or yum update --advisory ALAS2-2026-3877 to update your system.

New Packages:
aarch64:
    ipa-server-4.6.8-5.amzn2.17.5.aarch64
    ipa-server-trust-ad-4.6.8-5.amzn2.17.5.aarch64
    ipa-client-4.6.8-5.amzn2.17.5.aarch64
    ipa-debuginfo-4.6.8-5.amzn2.17.5.aarch64

i686:
    ipa-server-4.6.8-5.amzn2.17.5.i686
    ipa-server-trust-ad-4.6.8-5.amzn2.17.5.i686
    ipa-client-4.6.8-5.amzn2.17.5.i686
    ipa-debuginfo-4.6.8-5.amzn2.17.5.i686

noarch:
    python2-ipaserver-4.6.8-5.amzn2.17.5.noarch
    ipa-server-common-4.6.8-5.amzn2.17.5.noarch
    ipa-server-dns-4.6.8-5.amzn2.17.5.noarch
    python2-ipaclient-4.6.8-5.amzn2.17.5.noarch
    ipa-client-common-4.6.8-5.amzn2.17.5.noarch
    ipa-python-compat-4.6.8-5.amzn2.17.5.noarch
    python2-ipalib-4.6.8-5.amzn2.17.5.noarch
    ipa-common-4.6.8-5.amzn2.17.5.noarch

src:
    ipa-4.6.8-5.amzn2.17.5.src

x86_64:
    ipa-server-4.6.8-5.amzn2.17.5.x86_64
    ipa-server-trust-ad-4.6.8-5.amzn2.17.5.x86_64
    ipa-client-4.6.8-5.amzn2.17.5.x86_64
    ipa-debuginfo-4.6.8-5.amzn2.17.5.x86_64