---
id: CVE-2025-3576
title: >-
  A vulnerability in the MIT Kerberos implementation allows GSSAPI-protected
  messages using RC4-HMAC-MD5 to be spoofed due to weaknesses in the MD5
  checksum design
summary: >-
  A vulnerability in the MIT Kerberos implementation allows GSSAPI-protected
  messages using RC4-HMAC-MD5 to be spoofed due to weaknesses in the MD5
  checksum design. If RC4 is preferred over stronger encryption types, an
  attacker could expl…
severity: medium
cvss: 5.9
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N'
cwe:
  - CWE-328
published: '2025-04-15'
updated: '2026-06-25'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-3576'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2025:11487'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:13664'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:13777'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:15000'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:15001'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:15002'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:15003'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:15004'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:8411'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:9418'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:9430'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2025-3576'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2359465'
    label: secalert@redhat.com
  - url: 'https://web.mit.edu/kerberos/krb5-1.22/krb5-1.22.html'
    label: secalert@redhat.com
  - url: 'https://lists.debian.org/debian-lts-announce/2025/05/msg00047.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-577017.html'
    label: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
tags:
  - nvd
epss: 0.00345
epssPercentile: 0.28142
ingestedAt: '2026-06-29T13:24:34.194Z'
---

## Overview

A vulnerability in the MIT Kerberos implementation allows GSSAPI-protected messages using RC4-HMAC-MD5 to be spoofed due to weaknesses in the MD5 checksum design. If RC4 is preferred over stronger encryption types, an attacker could exploit MD5 collisions to forge message integrity codes. This may lead to unauthorized message tampering.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
