OESA-2025-2124

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2025-2124
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2025-2124.json
JSON Data
https://api.test.osv.dev/v1/vulns/OESA-2025-2124
Upstream
Published
2025-09-05T12:42:00Z
Modified
2025-09-05T13:03:27.490611Z
Summary
krb5 security update
Details

Kerberos is a network authentication protocol. It is designed to provide strong authentication for client/server applications by using secret-key cryptography.

Security Fix(es):

A vulnerability in the MIT Kerberos implementation allows GSSAPI-protected messages using RC4-HMAC-MD5 to be spoofed due to weaknesses in the MD5 checksum design. If RC4 is preferred over stronger encryption types, an attacker could exploit MD5 collisions to forge message integrity codes. This may lead to unauthorized message tampering.(CVE-2025-3576)

Database specific
{
    "severity": "Medium"
}
References

Affected packages

openEuler:22.03-LTS-SP3 / krb5

Package

Name
krb5
Purl
pkg:rpm/openEuler/krb5&distro=openEuler-22.03-LTS-SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.19.2-26.oe2203sp3

Ecosystem specific

{
    "noarch": [
        "krb5-help-1.19.2-26.oe2203sp3.noarch.rpm"
    ],
    "aarch64": [
        "krb5-1.19.2-26.oe2203sp3.aarch64.rpm",
        "krb5-client-1.19.2-26.oe2203sp3.aarch64.rpm",
        "krb5-debuginfo-1.19.2-26.oe2203sp3.aarch64.rpm",
        "krb5-debugsource-1.19.2-26.oe2203sp3.aarch64.rpm",
        "krb5-devel-1.19.2-26.oe2203sp3.aarch64.rpm",
        "krb5-libs-1.19.2-26.oe2203sp3.aarch64.rpm",
        "krb5-server-1.19.2-26.oe2203sp3.aarch64.rpm"
    ],
    "src": [
        "krb5-1.19.2-26.oe2203sp3.src.rpm"
    ],
    "x86_64": [
        "krb5-1.19.2-26.oe2203sp3.x86_64.rpm",
        "krb5-client-1.19.2-26.oe2203sp3.x86_64.rpm",
        "krb5-debuginfo-1.19.2-26.oe2203sp3.x86_64.rpm",
        "krb5-debugsource-1.19.2-26.oe2203sp3.x86_64.rpm",
        "krb5-devel-1.19.2-26.oe2203sp3.x86_64.rpm",
        "krb5-libs-1.19.2-26.oe2203sp3.x86_64.rpm",
        "krb5-server-1.19.2-26.oe2203sp3.x86_64.rpm"
    ]
}