CVE-2025-3576 Details
Description
A vulnerability in the MIT Kerberos implementation allows GSSAPI-protected messages using RC4-HMAC-MD5 to be spoofed due to weaknesses in the MD5 checksum design. If RC4 is preferred over stronger encryption types, an attacker could exploit MD5 collisions to forge message integrity codes. This may lead to unauthorized message tampering.
A vulnerability exists in the MIT Kerberos implementation that allows GSSAPI-protected messages using RC4-HMAC-MD5 to be spoofed. This issue arises from weaknesses in the MD5 checksum design, which can be exploited to forge message integrity codes. If RC4 is preferred over stronger encryption types, an attacker could manipulate messages without detection, leading to unauthorized tampering. The vulnerability affects several versions of the krb5 package in Red Hat Enterprise Linux 8, as well as in Red Hat Ansible Automation Platform 2. It requires a Kerberos environment with PKINIT enabled, and exploitation depends on specific memory allocation failures or parser behaviors, making the attack complex.
Users can upgrade to the patched krb5 version 1.18.3-6+deb11u7, available through the Red Hat Update System. For Red Hat Enterprise Linux 8, the update is included in the RHSA-2025:8411 advisory.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 15, 2025CISA-ADP
Assessed Apr 15, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-328 | Use of Weak Hash | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| MIT Kerberos | All versions |
CPE
Remediation
| |
| Red Hat Enterprise Linux | All versions |
CPE
Remediation
| |
| Debian | All versions |
CPE
Remediation
| |
Change History
23 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 1, 2026 | CVE Modified | [email protected] |
| Aug 31, 2026 | CVE Modified | [email protected] |
| Aug 31, 2026 | CVE Modified | CVE |
| Aug 31, 2026 | CVE Modified | siemens-SADP |
| Aug 21, 2026 | CVE Modified | [email protected] |
| Jun 30, 2026 | CVE Modified | [email protected] |
| Jun 25, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | siemens-SADP |
| May 12, 2026 | CVE Modified | siemens-SADP |
| Sep 2, 2025 | CVE Modified | [email protected] |
| Sep 2, 2025 | CVE Modified | [email protected] |
| Sep 2, 2025 | CVE Modified | [email protected] |
| Aug 13, 2025 | CVE Modified | [email protected] |
| Aug 12, 2025 | CVE Modified | [email protected] |
| Jul 28, 2025 | CVE Modified | [email protected] |
| Jul 21, 2025 | CVE Modified | [email protected] |
| Jun 24, 2025 | CVE Modified | [email protected] |
| Jun 24, 2025 | CVE Modified | [email protected] |
| Jun 3, 2025 | CVE Modified | [email protected] |
| May 30, 2025 | CVE Modified | CVE |
| Apr 15, 2025 | New CVE Received | [email protected] |
Volerion