Use of a broken or risky cryptographic algorithm in Kerberos - CVE-2025-3576

 

Use of a broken or risky cryptographic algorithm in Kerberos - CVE-2025-3576

Published: July 7, 2025


Vulnerability identifier: #VU112440
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-3576
CWE-ID: CWE-327
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform MitM attack.

The vulnerability exists due to usage of RC4-HMAC-MD algorithm for GSSAPI-protected messages. A remote attacker can perform MitM attack.


Affected software

Kerberos
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux Server - AUS
Ubuntu
Server Applications Module
Basesystem Module
openSUSE Leap
Fedora
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Netcool Operations Insight
Oracle Communications Network Analytics Data Director
Ansible Automation Platform
Red Hat Advanced Cluster Management for Kubernetes
Guardium Data Security Center (GDSC)
IBM Qradar SIEM
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
krb5 (Ubuntu package)
krb5-debuginfo
krb5-client-debuginfo
krb5-32bit
krb5-debuginfo-32bit
krb5-client
krb5-plugin-preauth-otp
krb5-server-debuginfo
krb5-debugsource
krb5-server
krb5-plugin-preauth-pkinit
krb5-plugin-kdb-ldap-debuginfo
krb5-doc
krb5
krb5-devel
krb5-plugin-kdb-ldap
krb5-plugin-preauth-otp-debuginfo
krb5-plugin-preauth-pkinit-debuginfo
krb5 (Red Hat package)
krb5-pkinit
krb5-libs
krb5-server-ldap
krb5-workstation
libkadm5
krb5-64bit-debuginfo
krb5-devel-64bit
krb5-64bit
krb5-32bit-debuginfo
krb5-devel-32bit
krb5-mini-debugsource
krb5-plugin-preauth-spake
krb5-plugin-preauth-spake-debuginfo
krb5-mini
krb5-mini-devel
krb5-mini-debuginfo
IBM API Connect
Red Hat OpenShift Serverless
Multicluster Engine for Kubernetes
OpenShift Virtualization
OpenShift API for Data Protection (OADP)
Red Hat OpenShift Container Platform
Red Hat Ceph Storage

How to mitigate CVE-2025-3576

Install updates from vendor's website.

Kerberos - update to 5-1.21
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.2.1
Netcool Operations Insight - update to 1.6.15
Guardium Data Security Center (GDSC) - update to 3.8.1
IBM Qradar SIEM - update to 7.5.0 Update Pack 13
IBM API Connect - update to 10.0.8.5
Red Hat OpenShift Serverless - update to 1
OpenShift API for Data Protection (OADP) - update to 1.4.5
krb5 (Ubuntu package) - addressed in versions 1.12+dfsg-2ubuntu5.4+esm7, 1.13.2+dfsg-5ubuntu2.2+esm7, 1.16-2ubuntu0.4+esm5, 1.17-6ubuntu4.11, 1.19.2-2ubuntu0.7, 1.20.1-6ubuntu2.6
krb5-debuginfo - addressed in versions 1.16.3-46.21.1, 1.19.2-150300.25.1, 1.19.2-150400.3.18.1, 1.20.1-150500.3.17.1, 1.20.1-150600.11.14.1
krb5-client-debuginfo - addressed in versions 1.16.3-46.21.1, 1.19.2-150300.25.1, 1.19.2-150400.3.18.1, 1.20.1-150500.3.17.1, 1.20.1-150600.11.14.1
krb5-32bit - addressed in versions 1.16.3-46.21.1, 1.19.2-150300.25.1, 1.19.2-150400.3.18.1, 1.20.1-150500.3.17.1, 1.20.1-150600.11.14.1
krb5-debuginfo-32bit - update to 1.16.3-46.21.1
krb5-client - addressed in versions 1.16.3-46.21.1, 1.19.2-150300.25.1, 1.19.2-150400.3.18.1, 1.20.1-150500.3.17.1, 1.20.1-150600.11.14.1
krb5-plugin-preauth-otp - addressed in versions 1.16.3-46.21.1, 1.19.2-150300.25.1, 1.19.2-150400.3.18.1, 1.20.1-150500.3.17.1, 1.20.1-150600.11.14.1
krb5-server-debuginfo - addressed in versions 1.16.3-46.21.1, 1.19.2-150300.25.1, 1.19.2-150400.3.18.1, 1.20.1-150500.3.17.1, 1.20.1-150600.11.14.1
krb5-debugsource - addressed in versions 1.16.3-46.21.1, 1.19.2-150300.25.1, 1.19.2-150400.3.18.1, 1.20.1-150500.3.17.1, 1.20.1-150600.11.14.1
krb5-server - addressed in versions 1.16.3-46.21.1, 1.19.2-150300.25.1, 1.19.2-150400.3.18.1, 1.20.1-150500.3.17.1, 1.20.1-150600.11.14.1
krb5-plugin-preauth-pkinit - addressed in versions 1.16.3-46.21.1, 1.19.2-150300.25.1, 1.19.2-150400.3.18.1, 1.20.1-150500.3.17.1, 1.20.1-150600.11.14.1
krb5-plugin-kdb-ldap-debuginfo - addressed in versions 1.16.3-46.21.1, 1.19.2-150300.25.1, 1.19.2-150400.3.18.1, 1.20.1-150500.3.17.1, 1.20.1-150600.11.14.1
krb5-doc - update to 1.16.3-46.21.1
krb5 - addressed in versions 1.16.3-46.21.1, 1.19.2-150300.25.1, 1.19.2-150400.3.18.1, 1.20.1-150500.3.17.1, 1.20.1-150600.11.14.1
krb5-devel - addressed in versions 1.16.3-46.21.1, 1.19.2-150300.25.1, 1.19.2-150400.3.18.1, 1.20.1-150500.3.17.1, 1.20.1-150600.11.14.1
krb5-plugin-kdb-ldap - addressed in versions 1.16.3-46.21.1, 1.19.2-150300.25.1, 1.19.2-150400.3.18.1, 1.20.1-150500.3.17.1, 1.20.1-150600.11.14.1
krb5-plugin-preauth-otp-debuginfo - addressed in versions 1.16.3-46.21.1, 1.19.2-150300.25.1, 1.19.2-150400.3.18.1, 1.20.1-150500.3.17.1, 1.20.1-150600.11.14.1
krb5-plugin-preauth-pkinit-debuginfo - addressed in versions 1.16.3-46.21.1, 1.19.2-150300.25.1, 1.19.2-150400.3.18.1, 1.20.1-150500.3.17.1, 1.20.1-150600.11.14.1
krb5 (Red Hat package) - addressed in versions 1.17-19.el8_2.3, 1.18.2-9.el8_4.3, 1.18.2-32.el8_10, 1.20.1-9.el9_2.3, 1.21.1-8.el9_6
krb5-pkinit - update to 1.18.2-32.0.1
krb5-devel - update to 1.18.2-32.0.1
krb5-libs - update to 1.18.2-32.0.1
krb5-server - update to 1.18.2-32.0.1
krb5-server-ldap - update to 1.18.2-32.0.1
krb5-workstation - update to 1.18.2-32.0.1
libkadm5 - update to 1.18.2-32.0.1
krb5-doc - update to 1.18.2-32.0.1
krb5-64bit-debuginfo - addressed in versions 1.19.2-150300.25.1, 1.19.2-150400.3.18.1, 1.20.1-150500.3.17.1, 1.20.1-150600.11.14.1
krb5-devel-64bit - addressed in versions 1.19.2-150300.25.1, 1.19.2-150400.3.18.1, 1.20.1-150500.3.17.1, 1.20.1-150600.11.14.1
krb5-64bit - addressed in versions 1.19.2-150300.25.1, 1.19.2-150400.3.18.1, 1.20.1-150500.3.17.1, 1.20.1-150600.11.14.1
krb5-32bit-debuginfo - addressed in versions 1.19.2-150300.25.1, 1.19.2-150400.3.18.1, 1.20.1-150500.3.17.1, 1.20.1-150600.11.14.1
krb5-devel-32bit - addressed in versions 1.19.2-150300.25.1, 1.19.2-150400.3.18.1, 1.20.1-150500.3.17.1, 1.20.1-150600.11.14.1
krb5-mini-debugsource - addressed in versions 1.19.2-150300.25.1, 1.19.2-150400.3.18.1, 1.20.1-150500.3.17.1, 1.20.1-150600.11.14.1
krb5-plugin-preauth-spake - addressed in versions 1.19.2-150300.25.1, 1.19.2-150400.3.18.1, 1.20.1-150500.3.17.1, 1.20.1-150600.11.14.1
krb5-plugin-preauth-spake-debuginfo - addressed in versions 1.19.2-150300.25.1, 1.19.2-150400.3.18.1, 1.20.1-150500.3.17.1, 1.20.1-150600.11.14.1
krb5-mini - addressed in versions 1.19.2-150300.25.1, 1.19.2-150400.3.18.1, 1.20.1-150500.3.17.1, 1.20.1-150600.11.14.1
krb5-mini-devel - addressed in versions 1.19.2-150300.25.1, 1.19.2-150400.3.18.1, 1.20.1-150500.3.17.1, 1.20.1-150600.11.14.1
krb5-mini-debuginfo - addressed in versions 1.19.2-150300.25.1, 1.19.2-150400.3.18.1, 1.20.1-150500.3.17.1, 1.20.1-150600.11.14.1
krb5 - addressed in versions 1.21.3-5.fc41, 1.21.3-6.fc42, 1.21.3-6.fc43
Ansible Automation Platform - update to 2.4
Multicluster Engine for Kubernetes - addressed in versions 2.6.8, 2.8.3
Red Hat Advanced Cluster Management for Kubernetes - update to 2.13.4
OpenShift Virtualization - update to 4.12.20
Red Hat OpenShift Container Platform - addressed in versions 4.14.53, 4.15.53
Red Hat Ceph Storage - update to 7.1

External References

Related Security Bulletins