REDHAT-BUG-2359465: Medium severity MIT Kerberos vulnerability

Published Apr 14, 2025
·
Updated

Under specific configurations where RC4-HMAC-MD5 is negotiated for GSSAPI-secured communication, attackers can sniff messages and use MD5 collision techniques to craft altered messages that retain the same MIC (Message Integrity Code). The vulnerable checksum function from RFC4757 allows this due to its flawed use of MD5. The attack relies on RC4 being chosen over stronger encryption options and presumes attacker access to the network traffic.

Affected Software

1 affected component
MIT Kerberos

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Update GSSAPI/Kerberos configuration so that RC4-HMAC-MD5 is not selected for the negotiated security context (avoid RC4 and the RFC4757 MD5-based vulnerable checksum/MIC construction).

    GSSAPI-secured communication (e.g., Kerberos GSSAPI negotiation using RC4-HMAC-MD5) Cipher/MIC algorithm negotiation = Do not negotiate or use RC4-HMAC-MD5; prefer stronger encryption algorithms than RC4-HMAC-MD5
  2. Compensating control

    Because the attack assumes attacker access to network traffic (sniffing), restrict and protect network paths used for GSSAPI-secured communication (e.g., isolate the network segment and limit access to only trusted hosts).

Event History

Apr 14, 2025
Data Sourced
via Red Hat·11:06 AM
DescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2359465?

The severity of REDHAT-BUG-2359465 is considered critical due to the potential for message alteration.

2

What causes REDHAT-BUG-2359465?

REDHAT-BUG-2359465 is caused by the use of the vulnerable RC4-HMAC-MD5 configuration in GSSAPI-secured communications.

3

How do I fix REDHAT-BUG-2359465?

To fix REDHAT-BUG-2359465, upgrade to a version that disables the use of RC4-HMAC-MD5 for GSSAPI communications.

4

Who is affected by REDHAT-BUG-2359465?

Organizations using GSSAPI with RC4-HMAC-MD5 configurations for secure communication are affected by REDHAT-BUG-2359465.

5

What are the potential consequences of REDHAT-BUG-2359465?

The potential consequences of REDHAT-BUG-2359465 include unauthorized message alteration and security breaches.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203