VDB
RHSA-2025:11487
RHSA-2025:11487
PUBLISHED
CVSS 7.800000190734863 HIGH
A vulnerability in the MIT Kerberos implementation allows GSSAPI-protected messages using RC4-HMAC-MD5 to be spoofed due to weaknesses in the MD5 checksum design. If RC4 is preferred over stronger encryption types, an attacker could exploit MD5 collisions to forge message integrity codes. This may lead to unauthorized message tampering.
Risk Scores
CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | registry.redhat.io/discovery/discovery-ui-rhel9@sha256:cb27ba3c1340e59001ddf83d311d952a4c11f9d4fa18bdab9f4a914370957948_amd64 as a component of Red Hat Discovery 2 | *, * |
| Red Hat | registry.redhat.io/discovery/discovery-server-rhel9@sha256:c499a099e03c7488ffe50529a34723ade191a89fcfc59d1f0edd01db2b579ca3_amd64 as a component of Red Hat Discovery 2 | *, * |
| Red Hat | registry.redhat.io/discovery/discovery-ui-rhel9@sha256:728ad644c83c3828f8bdc3b6aad9b1d30110f9911f0febcea5f0cfedc6b29dc7_arm64 as a component of Red Hat Discovery 2 | *, * |
| Red Hat | registry.redhat.io/discovery/discovery-server-rhel9@sha256:bd9cb502def3153c193713b56372694cb555a71b38d4fc0fd9d021bccc5602de_arm64 as a component of Red Hat Discovery 2 | *, * |
Timeline
- Jul 21, 2025 CVE Published
- Aug 2, 2026 Distribution Patch
- Aug 2, 2026 Security Advisory
- Aug 2, 2026 Security Advisory
- Aug 2, 2026 Security Advisory
- Aug 6, 2026 CVE Updated
- Aug 6, 2026 Distribution Patch
- Aug 6, 2026 Security Advisory
- Aug 6, 2026 Security Advisory
- Aug 6, 2026 Security Advisory
- Aug 6, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2025:11487 advisory
- https://access.redhat.com/security/cve/CVE-2024-53920 advisory
- https://access.redhat.com/security/cve/CVE-2025-25724 advisory
- https://access.redhat.com/security/cve/CVE-2025-3576 advisory
- https://access.redhat.com/security/cve/CVE-2025-4802 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2329161 issue
- https://www.cve.org/CVERecord?id=CVE-2025-3576 advisory
- https://web.mit.edu/kerberos/krb5-1.22/krb5-1.22.html advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2367468 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2370472 issue
- https://www.cve.org/CVERecord?id=CVE-2025-5702 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2372512 issue
- https://www.cve.org/CVERecord?id=CVE-2025-6020 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-6020 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2349221 issue
- https://www.cve.org/CVERecord?id=CVE-2025-25724 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-25724 advisory
- https://github.com/Ekkosun/pocs/blob/main/bsdtarbug exploit
- https://github.com/libarchive/libarchive/blob/b439d586f53911c84be5e380445a8a259e19114c/tar/util.c#L751-L752 advisory
- https://access.redhat.com/security/cve/CVE-2025-5702 advisory
…and 20 more