CVE-2025-3576

Updated: 2025-08-20 01:38:35.020783

Description:

A vulnerability in the MIT Kerberos implementation allows GSSAPI-protected messages using RC4-HMAC-MD5 to be spoofed due to weaknesses in the MD5 checksum design. If RC4 is preferred over stronger encryption types, an attacker could exploit MD5 collisions to forge message integrity codes. This may lead to unauthorized message tampering.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x NONE 0.0
CVSS Version 3.x MEDIUM 5.9

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU krb5 1.20.1 5.9 MEDIUM Released CLSA-2025:1756110212 2025-08-28 01:00:41
CentOS 8.4 ELS krb5 1.18.2-8.3 5.9 MEDIUM Released CLSA-2025:1751892444 2025-07-08 00:20:23
CentOS 8.5 ELS krb5 1.18.2-14 5.9 MEDIUM Released CLSA-2025:1751895517 2025-07-08 00:20:22
Ubuntu 16.04 ELS krb5 1.13.2 5.9 MEDIUM Released CLSA-2025:1755603427 2025-08-20 05:19:39
Ubuntu 18.04 ELS krb5 1.16-2 5.9 MEDIUM Released CLSA-2025:1755113592 2025-08-14 04:31:14
Ubuntu 20.04 ELS krb5 1.17 5.9 MEDIUM Ignored 2025-06-10 04:29:38 Ignored due to low severity