Krb5: kerberos rc4-hmac-md5 checksum vulnerability enabling message spoofing via md5 collisions
Published Apr 15, 2025
5.9
MEDIUMCVSS 3.1
EPSS 0.34%
Description
A vulnerability in the MIT Kerberos implementation allows GSSAPI-protected messages using RC4-HMAC-MD5 to be spoofed due to weaknesses in the MD5 checksum design. If RC4 is preferred over stronger encryption types, an attacker could exploit MD5 collisions to forge message integrity codes. This may lead to unauthorized message tampering.
Affected products
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Red Hat | Red Hat OpenShift Container Platform 4 | affected |
|
No data.
No data.
Red Hat Discovery 2
discovery/discovery-server-rhel9:2.0.0-1752592913
Fixed · RHSA-2025:11487
Red Hat Enterprise Linux 10
krb5-0:1.21.3-8.el10_0
Fixed · RHSA-2025:9418
Red Hat Enterprise Linux 8
krb5-0:1.18.2-32.el8_10
Fixed · RHSA-2025:8411
Red Hat Enterprise Linux 8.2 Advanced Update Support
krb5-0:1.17-19.el8_2.3
Fixed · RHSA-2025:15002
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
krb5-0:1.18.2-9.el8_4.3
Fixed · RHSA-2025:15003
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
krb5-0:1.18.2-9.el8_4.3
Fixed · RHSA-2025:15003
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
krb5-0:1.18.2-16.el8_6.4
Fixed · RHSA-2025:15001
Red Hat Enterprise Linux 8.6 Telecommunications Update Service
krb5-0:1.18.2-16.el8_6.4
Fixed · RHSA-2025:15001
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
krb5-0:1.18.2-16.el8_6.4
Fixed · RHSA-2025:15001
Red Hat Enterprise Linux 8.8 Telecommunications Update Service
krb5-0:1.18.2-26.el8_8.5
Fixed · RHSA-2025:15004
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
krb5-0:1.18.2-26.el8_8.5
Fixed · RHSA-2025:15004
Red Hat Enterprise Linux 9
krb5-0:1.21.1-8.el9_6
Fixed · RHSA-2025:9430
Red Hat Enterprise Linux 9
krb5-0:1.21.1-8.el9_6
Fixed · RHSA-2025:9430
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions
krb5-0:1.19.1-16.el9_0.4
Fixed · RHSA-2025:15000
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
krb5-0:1.20.1-9.el9_2.3
Fixed · RHSA-2025:13777
Red Hat Enterprise Linux 9.4 Extended Update Support
krb5-0:1.21.1-2.el9_4.2
Fixed · RHSA-2025:13664
Red Hat Enterprise Linux 6
krb5
Out of support scope
Red Hat Enterprise Linux 7
krb5
Out of support scope
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-8
Fix deferred
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-9
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Discovery 2 | discovery/discovery-server-rhel9:2.0.0-1752592913 | Fixed | RHSA-2025:11487 |
| Red Hat Enterprise Linux 10 | krb5-0:1.21.3-8.el10_0 | Fixed | RHSA-2025:9418 |
| Red Hat Enterprise Linux 8 | krb5-0:1.18.2-32.el8_10 | Fixed | RHSA-2025:8411 |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | krb5-0:1.17-19.el8_2.3 | Fixed | RHSA-2025:15002 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | krb5-0:1.18.2-9.el8_4.3 | Fixed | RHSA-2025:15003 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | krb5-0:1.18.2-9.el8_4.3 | Fixed | RHSA-2025:15003 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | krb5-0:1.18.2-16.el8_6.4 | Fixed | RHSA-2025:15001 |
| Red Hat Enterprise Linux 8.6 Telecommunications Update Service | krb5-0:1.18.2-16.el8_6.4 | Fixed | RHSA-2025:15001 |
| Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | krb5-0:1.18.2-16.el8_6.4 | Fixed | RHSA-2025:15001 |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | krb5-0:1.18.2-26.el8_8.5 | Fixed | RHSA-2025:15004 |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | krb5-0:1.18.2-26.el8_8.5 | Fixed | RHSA-2025:15004 |
| Red Hat Enterprise Linux 9 | krb5-0:1.21.1-8.el9_6 | Fixed | RHSA-2025:9430 |
| Red Hat Enterprise Linux 9 | krb5-0:1.21.1-8.el9_6 | Fixed | RHSA-2025:9430 |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | krb5-0:1.19.1-16.el9_0.4 | Fixed | RHSA-2025:15000 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | krb5-0:1.20.1-9.el9_2.3 | Fixed | RHSA-2025:13777 |
| Red Hat Enterprise Linux 9.4 Extended Update Support | krb5-0:1.21.1-2.el9_4.2 | Fixed | RHSA-2025:13664 |
| Red Hat Enterprise Linux 6 | krb5 | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | krb5 | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-9 | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Red Hat statement
This issue is classified as a moderate severity vulnerability because it affects the handling of PKINIT requests during ASN.1 decoding in krb5. Exploitation requires specific and uncommon configurations, including a Kerberos environment with PKINIT enabled. Additionally, successful exploitation depends on triggering specific memory allocation failures or parser behaviors, contributing to a high attack complexity.The attack requires that PKINIT is actively configured and in use, and cannot be exploited remotely without this setup in place, making the practical risk limited in standard environments.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (19)
- https://access.redhat.com/errata/RHSA-2025:11487 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:13664 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:13777 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:15000 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:15001 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:15002 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:15003 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:15004 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:8411 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:9418 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:9430 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2025-3576 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2359465 issue-trackingx_refsource_REDHATIssue Tracking
- https://cert-portal.siemens.com/productcert/html/ssa-577017.html
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-10925 Advisory
- https://lists.debian.org/debian-lts-announce/2025/05/msg00047.html
- https://nvd.nist.gov/vuln/detail/CVE-2025-3576
- https://web.mit.edu/kerberos/krb5-1.22/krb5-1.22.html
- https://www.cve.org/CVERecord?id=CVE-2025-3576
Change history (0)
No recorded changes yet.