Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Debian 11: DLA-4195-1 Critical: krb5 Spoofing Threat Mitigation

debian lts
Calendar Grey May 30, 2025
Dist Debian Esm H88
This notice outlines the latest krb5 patch for Debian LTS, which fixes a security flaw linked to spoofing vulnerabilities in GSSAPI communications due to MD5 weaknesses
A Vulnerability in the MIT Kerberos implementation allows GSSAPI-protected messages using RC4-HMAC-MD5 to be spoofed due to weaknesses in the MD5 checksum design

Summary

In order to fix CVE-2025-3576, vulnerable cryptographic
algorithms for tickets need to be disabled explicitly
with the new allow_rc4 or allow_des3 variables.

According to the vulnerability report "Kerberos’ RC4-HMAC broken
in practice: spoofing PACs with MD5 collisions", disabling
this cryptographic algorithm may break some older
authentication systems, and administrators should test carefully.

Because of the risk of breaking certain configurations, the
new allow_rc4 or allow_des3 are being treated as having a
default value of 'true' for updates to older Debian releases.
This leaves the 3DES and RC4 algorithms enabled, but administrators
are strongly encouraged to disable them after verifying
compatibility in their environments.

For Debian 11 bullseye, this problem has been fixed in version
1.18.3-6+deb11u7.

We recommend that you upgrade your krb5 packages.

For the detailed security status of krb5 please refer to
its security tracker page at:

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: krb5
Version: 1.18.3-6+deb11u7
CVE ID: CVE-2025-3576
Debian Bug: 1103525

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here