CVE-2025-3576

NameCVE-2025-3576
DescriptionA vulnerability in the MIT Kerberos implementation allows GSSAPI-protected messages using RC4-HMAC-MD5 to be spoofed due to weaknesses in the MD5 checksum design. If RC4 is preferred over stronger encryption types, an attacker could exploit MD5 collisions to forge message integrity codes. This may lead to unauthorized message tampering.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
krb5 (PTS)bullseye1.18.3-6+deb11u5vulnerable
bullseye (security)1.18.3-6+deb11u6vulnerable
bookworm, bookworm (security)1.20.1-2+deb12u2vulnerable
sid, trixie1.21.3-5vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
krb5source(unstable)(unfixed)

Notes

https://bugzilla.redhat.com/show_bug.cgi?id=2359465
check upstream details

Search for package or bug name: Reporting problems