CVE-2026-25506
published 2026-02-10CVE-2026-25506: MUNGE is an authentication service for creating and validating user credentials. From 0.5 to 0.5.17, local attacker can exploit a buffer overflow vulnerability…
PriorityP351high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.30%
22.6th percentile
MUNGE is an authentication service for creating and validating user credentials. From 0.5 to 0.5.17, local attacker can exploit a buffer overflow vulnerability in munged (the MUNGE authentication daemon) to leak cryptographic key material from process memory. With the leaked key material, the attacker could forge arbitrary MUNGE credentials to impersonate any user (including root) to services that rely on MUNGE for authentication. The vulnerability allows a buffer overflow by sending a crafted message with an oversized address length field, corrupting munged's internal state and enabling extraction of the MAC subkey used for credential verification. This vulnerability is fixed in 0.5.18.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | munge | < munge 0.5.15-2+deb12u1 (bookworm) | munge 0.5.15-2+deb12u1 (bookworm) |
| dun | munge | — | — |
| opensuse | munge | >= 0 < 0.5.14-4+deb11u1 | 0.5.14-4+deb11u1 |
| opensuse | munge | >= 0 < 0.5.15-2+deb12u1 | 0.5.15-2+deb12u1 |
| opensuse | munge | >= 0 < 0.5.16-1.1~deb13u1 | 0.5.16-1.1~deb13u1 |
| opensuse | munge | >= 0 < 0.5.16-1.1 | 0.5.16-1.1 |
| opensuse | munge | >= 0.5 < 0.5.18 | 0.5.18 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.7HIGH
vendor_redhat7.7HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
MUNGE vulnerability
vendor_ubuntu·2026-02-12
CVE-2026-25506 MUNGE vulnerability
Title: MUNGE vulnerability
Summary: MUNGE could be made to crash or run programs as your login if it opened a
specially crafted file.
Titouan Lazard discovered that MUNGE contained an exploitable buffer
overflow in munged (the MUNGE authentication daemon). A local attacker
could possibly use this issue to forge MUNGE credentials, leading to
arbitrary code execution.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
MUNGE: MUNGE has a buffer overflow in message unpacking allows key leakage and credential forgery
vendor_redhat·2026-02-10·CVSS 7.7
CVE-2026-25506 [HIGH] CWE-120 MUNGE: MUNGE has a buffer overflow in message unpacking allows key leakage and credential forgery
MUNGE: MUNGE has a buffer overflow in message unpacking allows key leakage and credential forgery
MUNGE is an authentication service for creating and validating user credentials. From 0.5 to 0.5.17, local attacker can exploit a buffer overflow vulnerability in munged (the MUNGE authentication daemon) to leak cryptographic key material from process memory. With the leaked key material, the attacker could forge arbitrary MUNGE credentials to impersonate any user (including root) to services that rely on MUNGE for authentication. The vulnerability allows a buffer overflow by sending a crafted message with an oversized address length field, corrupting munged's internal state and enabling extraction of the MAC subkey used for credential verification. This vulnerability is fixed in 0.5.18.
A b
Debian
CVE-2026-25506: munge - MUNGE is an authentication service for creating and validating user credentials....
vendor_debian·2026·CVSS 7.7
CVE-2026-25506 [HIGH] CVE-2026-25506: munge - MUNGE is an authentication service for creating and validating user credentials....
MUNGE is an authentication service for creating and validating user credentials. From 0.5 to 0.5.17, local attacker can exploit a buffer overflow vulnerability in munged (the MUNGE authentication daemon) to leak cryptographic key material from process memory. With the leaked key material, the attacker could forge arbitrary MUNGE credentials to impersonate any user (including root) to services that rely on MUNGE for authentication. The vulnerability allows a buffer overflow by sending a crafted message with an oversized address length field, corrupting munged's internal state and enabling extraction of the MAC subkey used for credential verification. This vulnerability is fixed in 0.5.18.
Scope: local
bookworm: resolved (fixed in 0.5.15-2+deb12u1)
bullseye: resolved (fixed in 0.5.14-4+deb11
OSV
CVE-2026-25506: MUNGE is an authentication service for creating and validating user credentials
osv·2026-02-10·CVSS 7.8
CVE-2026-25506 [HIGH] CVE-2026-25506: MUNGE is an authentication service for creating and validating user credentials
MUNGE is an authentication service for creating and validating user credentials. From 0.5 to 0.5.17, local attacker can exploit a buffer overflow vulnerability in munged (the MUNGE authentication daemon) to leak cryptographic key material from process memory. With the leaked key material, the attacker could forge arbitrary MUNGE credentials to impersonate any user (including root) to services that rely on MUNGE for authentication. The vulnerability allows a buffer overflow by sending a crafted message with an oversized address length field, corrupting munged's internal state and enabling extraction of the MAC subkey used for credential verification. This vulnerability is fixed in 0.5.18.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-25506 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.7
CVE-2026-25506 [HIGH] CVE-2026-25506 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-25506 :
NixOS vulnerability analysis and mitigation
MUNGE is an authentication service for creating and validating user credentials. From 0.5 to 0.5.17, local attacker can exploit a buffer overflow vulnerability in munged (the MUNGE authentication daemon) to leak cryptographic key material from process memory. With the leaked key material, the attacker could forge arbitrary MUNGE credentials to impersonate any user (including root) to services that rely on MUNGE for authentication. The vulnerability allows a buffer overflow by sending a crafted message with an oversized address length field, corrupting munged's internal state and enabling extraction of the MAC subkey used for credential verification. This vulnerability is fixed in 0.5.18.
Source : NVD
## 7.8
Score
Publi
Bugzilla
CVE-2026-25506 MUNGE: MUNGE has a buffer overflow in message unpacking allows key leakage and credential forgery
bugzilla·2026-02-10·CVSS 7.8
CVE-2026-25506 [HIGH] CVE-2026-25506 MUNGE: MUNGE has a buffer overflow in message unpacking allows key leakage and credential forgery
CVE-2026-25506 MUNGE: MUNGE has a buffer overflow in message unpacking allows key leakage and credential forgery
MUNGE is an authentication service for creating and validating user credentials. From 0.5 to 0.5.17, local attacker can exploit a buffer overflow vulnerability in munged (the MUNGE authentication daemon) to leak cryptographic key material from process memory. With the leaked key material, the attacker could forge arbitrary MUNGE credentials to impersonate any user (including root) to services that rely on MUNGE for authentication. The vulnerability allows a buffer overflow by sending a crafted message with an oversized address length field, corrupting munged's internal state and enabling extraction of the MAC subkey used for credential verification. This vulnerability is fixed
https://github.com/dun/munge/commit/bf40cc27c4ce8451d4b062c9de0b67ec40894812https://github.com/dun/munge/releases/tag/munge-0.5.18https://github.com/dun/munge/security/advisories/GHSA-r9cr-jf4v-75ghhttp://www.openwall.com/lists/oss-security/2026/02/10/3http://www.openwall.com/lists/oss-security/2026/02/17/6https://lists.debian.org/debian-lts-announce/2026/02/msg00015.htmlhttps://access.redhat.com/errata/RHSA-2026:16174https://access.redhat.com/errata/RHSA-2026:2918https://access.redhat.com/errata/RHSA-2026:2923https://access.redhat.com/errata/RHSA-2026:2934https://access.redhat.com/errata/RHSA-2026:2949https://access.redhat.com/errata/RHSA-2026:2954https://access.redhat.com/errata/RHSA-2026:3010https://access.redhat.com/errata/RHSA-2026:3011https://access.redhat.com/errata/RHSA-2026:3012https://access.redhat.com/errata/RHSA-2026:3013https://access.redhat.com/errata/RHSA-2026:3032https://access.redhat.com/errata/RHSA-2026:3033https://access.redhat.com/errata/RHSA-2026:3034https://access.redhat.com/security/cve/CVE-2026-25506https://bugzilla.redhat.com/show_bug.cgi?id=2438715https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25506.json
2026-02-10
Published