<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 15:26:15 +0000</lastBuildDate>
    <item>
      <title>ALSA-2025:8411 — Moderate: krb5 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2025:8411</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: krb5-devel, AlmaLinux:8: krb5-libs, AlmaLinux:8: krb5-pkinit, AlmaLinux:8: krb5-server, AlmaLinux:8: krb5-server-ldap, AlmaLinux:8: krb5-workstation, AlmaLinux:8: libkadm5&lt;/p&gt;
&lt;p&gt;Kerberos is a network authentication system, which can improve the security of your network by eliminating the insecure practice of sending passwords over the network in unencrypted form. It allows clients and servers to authenticate to each other with the help of a trusted third party, the Kerberos key distribution center (KDC).&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* krb5: Kerberos RC4-HMAC-MD5 Checksum Vulnerability Enabling Message Spoofing via MD5 Collisions (CVE-2025-3576)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: krb5-devel, AlmaLinux:8: krb5-libs, AlmaLinux:8: krb5-pkinit, AlmaLinux:8: krb5-server, AlmaLinux:8: krb5-server-ldap, AlmaLinux:8: krb5-workstation, AlmaLinux:8: libkadm5&lt;/p&gt;
&lt;p&gt;Kerberos is a network authentication system, which can improve the security of your network by eliminating the insecure practice of sending passwords over the network in unencrypted form. It allows clients and servers to authenticate to each other with the help of a trusted third party, the Kerberos key distribution center (KDC).&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* krb5: Kerberos RC4-HMAC-MD5 Checksum Vulnerability Enabling Message Spoofing via MD5 Collisions (CVE-2025-3576)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2025:8411</guid>
    </item>
    <item>
      <title>bdu:2025-10927</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-10927</link>
      <description>bdu:2025-10927</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-10927</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0585 — De multiples vulnérabilités ont été découvertes dans VMware Tanzu. Certaines d'entre elles permettent à un attaquant de…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0585</link>
      <description>certfr-2025-avi-0585</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0585</guid>
    </item>
    <item>
      <title>EUVD-2026-362215</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-362215</link>
      <description>EUVD-2026-362215</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-362215</guid>
    </item>
    <item>
      <title>fkie_cve-2025-3576</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-3576</link>
      <description>&lt;p&gt;A vulnerability in the MIT Kerberos implementation allows GSSAPI-protected messages using RC4-HMAC-MD5 to be spoofed due to weaknesses in the MD5 checksum design. If RC4 is preferred over stronger encryption types, an attacker could exploit MD5 collisions to forge message integrity codes. This may lead to unauthorized message tampering.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability in the MIT Kerberos implementation allows GSSAPI-protected messages using RC4-HMAC-MD5 to be spoofed due to weaknesses in the MD5 checksum design. If RC4 is preferred over stronger encryption types, an attacker could exploit MD5 collisions to forge message integrity codes. This may lead to unauthorized message tampering.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-3576</guid>
    </item>
    <item>
      <title>GHSA-rfh5-gx7w-h7v7</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-rfh5-gx7w-h7v7</link>
      <description>&lt;p&gt;A vulnerability in the MIT Kerberos implementation allows GSSAPI-protected messages using RC4-HMAC-MD5 to be spoofed due to weaknesses in the MD5 checksum design. If RC4 is preferred over stronger encryption types, an attacker could exploit MD5 collisions to forge message integrity codes. This may lead to unauthorized message tampering.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability in the MIT Kerberos implementation allows GSSAPI-protected messages using RC4-HMAC-MD5 to be spoofed due to weaknesses in the MD5 checksum design. If RC4 is preferred over stronger encryption types, an attacker could exploit MD5 collisions to forge message integrity codes. This may lead to unauthorized message tampering.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-rfh5-gx7w-h7v7</guid>
    </item>
    <item>
      <title>ICSA-26-134-16 — Siemens Ruggedcom Rox</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-26-134-16</link>
      <description>&lt;p&gt;A crafted self-referential DOS partition table will cause all Das U-Boot versions through 2019.07-rc4 to infinitely recurse, causing the stack to grow infinitely and eventually either crash or overwrite other data. In Das U-Boot versions 2016.11-rc1 through 2019.07-rc4, an underflow can cause memcpy() to overwrite a very large amount of data (including the whole stack) while reading a crafted ext4 filesystem. Das U-Boot versions 2016.09 through 2019.07-rc4 can memset() too much data while reading a crafted ext4 filesystem, which results in a stack buffer overflow and likely code execution. An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy when parsing a UDP packet due to a net_process_received_packet integer underflow during an nc_input_packet call. An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy with an unvalidated length at nfs_readlink_reply, in the &amp;#34;if&amp;#34; block after calculating the new path length. An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy with a failed length check at nfs_read_reply when calling store_block in the NFSv2 case. An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy with unvalidated length at nfs_readlink_reply in the &amp;#34;else&amp;#34; block after calculating the new path length. An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy with a failed length check at nfs_lookup_reply. An issue was discove…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A crafted self-referential DOS partition table will cause all Das U-Boot versions through 2019.07-rc4 to infinitely recurse, causing the stack to grow infinitely and eventually either crash or overwrite other data. In Das U-Boot versions 2016.11-rc1 through 2019.07-rc4, an underflow can cause memcpy() to overwrite a very large amount of data (including the whole stack) while reading a crafted ext4 filesystem. Das U-Boot versions 2016.09 through 2019.07-rc4 can memset() too much data while reading a crafted ext4 filesystem, which results in a stack buffer overflow and likely code execution. An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy when parsing a UDP packet due to a net_process_received_packet integer underflow during an nc_input_packet call. An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy with an unvalidated length at nfs_readlink_reply, in the &amp;#34;if&amp;#34; block after calculating the new path length. An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy with a failed length check at nfs_read_reply when calling store_block in the NFSv2 case. An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy with unvalidated length at nfs_readlink_reply in the &amp;#34;else&amp;#34; block after calculating the new path length. An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy with a failed length check at nfs_lookup_reply. An issue was discove…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-26-134-16</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-3576 — Krb5: kerberos rc4-hmac-md5 checksum vulnerability enabling message spoofing via md5 collisions</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-3576</link>
      <description>msrc_CVE-2025-3576</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-3576</guid>
    </item>
    <item>
      <title>NCSC-2026-0147 — Kwetsbaarheden verholpen in Siemens-producten</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0147</link>
      <description>NCSC-2026-0147</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0147</guid>
    </item>
    <item>
      <title>OESA-2025-2124 — krb5 security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-2124</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: krb5&lt;/p&gt;
&lt;p&gt;Kerberos is a network authentication protocol. It is designed to provide strong authentication for client/server applications by using secret-key cryptography.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A vulnerability in the MIT Kerberos implementation allows GSSAPI-protected messages using RC4-HMAC-MD5 to be spoofed due to weaknesses in the MD5 checksum design. If RC4 is preferred over stronger encryption types, an attacker could exploit MD5 collisions to forge message integrity codes. This may lead to unauthorized message tampering.(CVE-2025-3576)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: krb5&lt;/p&gt;
&lt;p&gt;Kerberos is a network authentication protocol. It is designed to provide strong authentication for client/server applications by using secret-key cryptography.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A vulnerability in the MIT Kerberos implementation allows GSSAPI-protected messages using RC4-HMAC-MD5 to be spoofed due to weaknesses in the MD5 checksum design. If RC4 is preferred over stronger encryption types, an attacker could exploit MD5 collisions to forge message integrity codes. This may lead to unauthorized message tampering.(CVE-2025-3576)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-2124</guid>
    </item>
    <item>
      <title>RHSA-2025:11487 — Red Hat Security Advisory: A Subscription Management tool for finding and reporting Red Hat product usage</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:11487</link>
      <description>&lt;p&gt;emacs: arbitrary code execution via Lisp macro expansion krb5: Kerberos RC4-HMAC-MD5 Checksum Vulnerability Enabling Message Spoofing via MD5 Collisions glibc: static setuid binary dlopen may incorrectly search LD_LIBRARY_PATH glibc: Vector register overwrite bug in glibc linux-pam: Linux-pam directory Traversal libarchive: Buffer Overflow vulnerability in libarchive&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;emacs: arbitrary code execution via Lisp macro expansion krb5: Kerberos RC4-HMAC-MD5 Checksum Vulnerability Enabling Message Spoofing via MD5 Collisions glibc: static setuid binary dlopen may incorrectly search LD_LIBRARY_PATH glibc: Vector register overwrite bug in glibc linux-pam: Linux-pam directory Traversal libarchive: Buffer Overflow vulnerability in libarchive&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:11487</guid>
    </item>
    <item>
      <title>RHSA-2025:8411 — Red Hat Security Advisory: krb5 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:8411</link>
      <description>&lt;p&gt;krb5: Kerberos RC4-HMAC-MD5 Checksum Vulnerability Enabling Message Spoofing via MD5 Collisions&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;krb5: Kerberos RC4-HMAC-MD5 Checksum Vulnerability Enabling Message Spoofing via MD5 Collisions&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:8411</guid>
    </item>
    <item>
      <title>SSA-577017 — SSA-577017: Multiple Vulnerabilities in Ruggedcom Rox Before 2.17.1</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-577017</link>
      <description>&lt;p&gt;A crafted self-referential DOS partition table will cause all Das U-Boot versions through 2019.07-rc4 to infinitely recurse, causing the stack to grow infinitely and eventually either crash or overwrite other data. In Das U-Boot versions 2016.11-rc1 through 2019.07-rc4, an underflow can cause memcpy() to overwrite a very large amount of data (including the whole stack) while reading a crafted ext4 filesystem. Das U-Boot versions 2016.09 through 2019.07-rc4 can memset() too much data while reading a crafted ext4 filesystem, which results in a stack buffer overflow and likely code execution. An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy when parsing a UDP packet due to a net_process_received_packet integer underflow during an nc_input_packet call. An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy with an unvalidated length at nfs_readlink_reply, in the &amp;#34;if&amp;#34; block after calculating the new path length. An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy with a failed length check at nfs_read_reply when calling store_block in the NFSv2 case. An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy with unvalidated length at nfs_readlink_reply in the &amp;#34;else&amp;#34; block after calculating the new path length. An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy with a failed length check at nfs_lookup_reply. An issue was discove…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A crafted self-referential DOS partition table will cause all Das U-Boot versions through 2019.07-rc4 to infinitely recurse, causing the stack to grow infinitely and eventually either crash or overwrite other data. In Das U-Boot versions 2016.11-rc1 through 2019.07-rc4, an underflow can cause memcpy() to overwrite a very large amount of data (including the whole stack) while reading a crafted ext4 filesystem. Das U-Boot versions 2016.09 through 2019.07-rc4 can memset() too much data while reading a crafted ext4 filesystem, which results in a stack buffer overflow and likely code execution. An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy when parsing a UDP packet due to a net_process_received_packet integer underflow during an nc_input_packet call. An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy with an unvalidated length at nfs_readlink_reply, in the &amp;#34;if&amp;#34; block after calculating the new path length. An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy with a failed length check at nfs_read_reply when calling store_block in the NFSv2 case. An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy with unvalidated length at nfs_readlink_reply in the &amp;#34;else&amp;#34; block after calculating the new path length. An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy with a failed length check at nfs_lookup_reply. An issue was discove…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-577017</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:03227-1 — Security update for krb5</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:03227-1</link>
      <description>&lt;p&gt;Security update for krb5&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for krb5&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:03227-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-3576</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-3576</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: krb5, Ubuntu:Pro:16.04:LTS: krb5, Ubuntu:Pro:18.04:LTS: krb5, Ubuntu:20.04:LTS: krb5, Ubuntu:22.04:LTS: krb5, Ubuntu:24.04:LTS: krb5&lt;/p&gt;
&lt;p&gt;A vulnerability in the MIT Kerberos implementation allows GSSAPI-protected messages using RC4-HMAC-MD5 to be spoofed due to weaknesses in the MD5 checksum design. If RC4 is preferred over stronger encryption types, an attacker could exploit MD5 collisions to forge message integrity codes. This may lead to unauthorized message tampering.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: krb5, Ubuntu:Pro:16.04:LTS: krb5, Ubuntu:Pro:18.04:LTS: krb5, Ubuntu:20.04:LTS: krb5, Ubuntu:22.04:LTS: krb5, Ubuntu:24.04:LTS: krb5&lt;/p&gt;
&lt;p&gt;A vulnerability in the MIT Kerberos implementation allows GSSAPI-protected messages using RC4-HMAC-MD5 to be spoofed due to weaknesses in the MD5 checksum design. If RC4 is preferred over stronger encryption types, an attacker could exploit MD5 collisions to forge message integrity codes. This may lead to unauthorized message tampering.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-3576</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-0795 — MIT Kerberos: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0795</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in MIT Kerberos ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in MIT Kerberos ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0795</guid>
    </item>
  </channel>
</rss>
