Amazon Linux 2 (EOS) Security Advisory: ALAS2-2026-3950
Advisory Released Date: 2026-09-28
Advisory Updated Date: 2026-09-28
A flaw was found in FreeIPA. An unauthenticated remote attacker could exploit a DOM Cross-Site Scripting (XSS) vulnerability in the FreeIPA/IdM Web UI password reset page. By enticing a victim to click a specially crafted link and complete a password reset, the attacker could inject and execute arbitrary JavaScript code. This allows the attacker to perform actions within the victim's authenticated session, potentially leading to full administrative control if an IdM administrator is targeted. (CVE-2026-18147)
A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by sending oversized form POST requests to the `/ipa/migration/migration.py` endpoint. This can force the migration handler to read attacker-controlled request bodies fully into memory, leading to increased memory usage, slower request handling, and potential service disruption or denial of service. (CVE-2026-73197)
Affected Packages:
ipa
Note:
This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.
Issue Correction:
Run yum update ipa or yum update --advisory ALAS2-2026-3950 to update your system.
aarch64:
ipa-server-4.6.8-5.amzn2.17.8.aarch64
ipa-server-trust-ad-4.6.8-5.amzn2.17.8.aarch64
ipa-client-4.6.8-5.amzn2.17.8.aarch64
ipa-debuginfo-4.6.8-5.amzn2.17.8.aarch64
i686:
ipa-server-4.6.8-5.amzn2.17.8.i686
ipa-server-trust-ad-4.6.8-5.amzn2.17.8.i686
ipa-client-4.6.8-5.amzn2.17.8.i686
ipa-debuginfo-4.6.8-5.amzn2.17.8.i686
noarch:
python2-ipaserver-4.6.8-5.amzn2.17.8.noarch
ipa-server-common-4.6.8-5.amzn2.17.8.noarch
ipa-server-dns-4.6.8-5.amzn2.17.8.noarch
python2-ipaclient-4.6.8-5.amzn2.17.8.noarch
ipa-client-common-4.6.8-5.amzn2.17.8.noarch
ipa-python-compat-4.6.8-5.amzn2.17.8.noarch
python2-ipalib-4.6.8-5.amzn2.17.8.noarch
ipa-common-4.6.8-5.amzn2.17.8.noarch
src:
ipa-4.6.8-5.amzn2.17.8.src
x86_64:
ipa-server-4.6.8-5.amzn2.17.8.x86_64
ipa-server-trust-ad-4.6.8-5.amzn2.17.8.x86_64
ipa-client-4.6.8-5.amzn2.17.8.x86_64
ipa-debuginfo-4.6.8-5.amzn2.17.8.x86_64