VDB

RHSA-2025:11487

RHSA-2025:11487 PUBLISHED CVSS 7.800000190734863 HIGH

A vulnerability in the MIT Kerberos implementation allows GSSAPI-protected messages using RC4-HMAC-MD5 to be spoofed due to weaknesses in the MD5 checksum design. If RC4 is preferred over stronger encryption types, an attacker could exploit MD5 collisions to forge message integrity codes. This may lead to unauthorized message tampering.

Risk Scores

CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Red Hatregistry.redhat.io/discovery/discovery-ui-rhel9@sha256:cb27ba3c1340e59001ddf83d311d952a4c11f9d4fa18bdab9f4a914370957948_amd64 as a component of Red Hat Discovery 2*, *
Red Hatregistry.redhat.io/discovery/discovery-server-rhel9@sha256:c499a099e03c7488ffe50529a34723ade191a89fcfc59d1f0edd01db2b579ca3_amd64 as a component of Red Hat Discovery 2*, *
Red Hatregistry.redhat.io/discovery/discovery-ui-rhel9@sha256:728ad644c83c3828f8bdc3b6aad9b1d30110f9911f0febcea5f0cfedc6b29dc7_arm64 as a component of Red Hat Discovery 2*, *
Red Hatregistry.redhat.io/discovery/discovery-server-rhel9@sha256:bd9cb502def3153c193713b56372694cb555a71b38d4fc0fd9d021bccc5602de_arm64 as a component of Red Hat Discovery 2*, *

Timeline

  • Jul 21, 2025 CVE Published
  • Aug 2, 2026 Distribution Patch
  • Aug 2, 2026 Security Advisory
  • Aug 2, 2026 Security Advisory
  • Aug 2, 2026 Security Advisory
  • Aug 6, 2026 CVE Updated
  • Aug 6, 2026 Distribution Patch
  • Aug 6, 2026 Security Advisory
  • Aug 6, 2026 Security Advisory
  • Aug 6, 2026 Security Advisory
  • Aug 6, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›