关键信息 漏洞概述 类型/严重性: 安全公告 - 中等 主题: krb5 安全更新 描述: Kerberos RC4-HMAC-MD5 校验和漏洞允许通过 MD5 碰撞进行消息伪造 (CVE-2025-3576) 影响的产品 Red Hat Enterprise Linux for x86_64 10 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.0 x86_64 Red Hat Enterprise Linux for IBM z Systems 10 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.0 s390x Red Hat Enterprise Linux for Power, little endian 10 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.0 ppc64le Red Hat Enterprise Linux for ARM 64.0 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.0 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.0 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.0 s390x Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.0 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.0 x86_64 修复措施 RHSA-2025:4605 - CVE-2025-3576 krb5: Kerberos RC4-HMAC-MD5 Checksum Vulnerability Enabling Message Spoofing via MD5 Collisions RHEL-74205 - PKINIT: implement paChecksum2 from MS-PKCA v20230920 [rhel-10] RHEL-88047 - CVE-2025-3576: RC4 HMAC-MD5 checksum vulnerability enabling GSSAPI-protected message spoofing via MD5 collisions [rhel-10] CVEs CVE-2025-3576 参考链接 https://access.redhat.com/security/updates/classification/#moderate