High Severity Vulnerability
This vulnerability has been rated as High severity. Immediate action is recommended.
CVE-2026-25506
HighVulnerability Description
MUNGE is an authentication service for creating and validating user credentials. From 0.5 to 0.5.17, local attacker can exploit a buffer overflow vulnerability in munged (the MUNGE authentication daemon) to leak cryptographic key material from process memory. With the leaked key material, the attacker could forge arbitrary MUNGE credentials to impersonate any user (including root) to services that rely on MUNGE for authentication. The vulnerability allows a buffer overflow by sending a crafted message with an oversized address length field, corrupting munged's internal state and enabling extraction of the MAC subkey used for credential verification. This vulnerability is fixed in 0.5.18.
CVSS Metrics
Common Vulnerability Scoring System
Vector String:
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L
Known Affected Software
1 configuration(s) from 1 vendor(s)
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
CVE-2026-25506
CVE-2026-25506
USN-8040-1
USN-8040-1: MUNGE vulnerability
References & Resources
-
https://github.com/dun/munge/commit/bf40cc27c4ce8451d4b062c9de0b67ec40894812security-advisories@github.com Patch
-
https://github.com/dun/munge/releases/tag/munge-0.5.18security-advisories@github.com Product Release Notes
-
https://github.com/dun/munge/security/advisories/GHSA-r9cr-jf4v-75ghsecurity-advisories@github.com Mitigation Patch Vendor Advisory
-
http://www.openwall.com/lists/oss-security/2026/02/10/3af854a3a-2127-422b-91ae-364da2661108 Mailing List Patch Third Party Advisory
-
http://www.openwall.com/lists/oss-security/2026/02/17/6af854a3a-2127-422b-91ae-364da2661108 Mailing List Third Party Advisory
-
https://lists.debian.org/debian-lts-announce/2026/02/msg00015.htmlaf854a3a-2127-422b-91ae-364da2661108 Mailing List Third Party Advisory
Severity Details
Weakness Type (CWE)
Out-of-bounds Write
- Description
- The product writes data past the end, or before the beginning, of the intended buffer.
- Exploit Likelihood
- High
- Typical Severity
- High
- Abstraction Level
- Base
Key Information
- Published Date
- February 10, 2026
