Skip to content
Fedora 43 FreeIPA Security Fixes Multiple CVEs 2026

Fedora 43 FreeIPA Security Fixes Multiple CVEs 2026

Linuxsecurity LinuxSecurity Advisories August 7, 2026

Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges ×

IPA is an integrated solution to provide centrally managed Identity (users,

hosts, services), Authentication (SSO, 2FA), and Authorization

(host access control, SELinux user roles, services). The solution provides

features for further integration with Linux based clients (SUDO, automount)

and integration with Active Directory based infrastructures (Trusts).

Update to Samba 4.23.10 (and rebuild of FreeIPA). Security fixes for CVE-2026-6949, CVE-2026-58218, CVE-2026-58221, CVE-2026-58222, CVE-2026-58216 and CVE-2026-58224

* Mon Aug 3 2026 Alexander Bokovoy - 4.13.2-1 - FreeIPA 4.13.2

* Mon Aug 3 2026 Alexander Bokovoy - 4.13.2-1 - FreeIPA 4.13.2

[ 1 ] Bug #2509257 - CVE-2026-6949 samba: TSIG packet with crafted name compression can crash DNS server [fedora-all] [ 2 ] Bug #2509266 - CVE-2026-58218 samba: DNS signing DoS via TKEY name cache exhaustion [fedora-all] [ 3 ] Bug #2509280 - CVE-2026-58221 samba: authenticated LDAP access to internal LDB special DNs permits domain takeover [fedora-all] [ 4 ] Bug #2509502 - CVE-2026-58222 samba: Samba AD LDAP Compare filter injection and trusted-request confusion disclose protected attributes [fedora-all] [ 5 ] Bug #2510884 - CVE-2026-58216 samba: kpasswd service: kpasswd packet that contains malformed ASN.1 might cause the server to access 6 bytes of unallocated memory leading server to crash [fedora-all]

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-8e7fa96cf3' at the command line. For more information, refer to the dnf documentation available at

Get the latest Linux and open source security news straight to your inbox.