Security News

Cybersecurity news aggregator

🐧
MEDIUM Vulnerabilities Web Discovery

Rapid7

  • What: A buffer overflow vulnerability exists in MUNGE versions 0.5 to 0.5.17 that could allow a local attacker to leak cryptographic key material from process memory.
  • Impact: An attacker could forge arbitrary MUNGE credentials to impersonate any user, including root, to services that rely on MUNGE for authentication.
  • CVE: CVE-2026-25506
Read Full Article →

vulnerability Debian: CVE-2026-25506: munge -- security update Try Surface Command Back to search Severity CVSS Published Added Modified 6 (AV:L/AC:M/Au:S/C:C/I:C/A:P) Feb 12, 2026 Feb 12, 2026 Feb 13, 2026 Severity 6 CVSS (AV:L/AC:M/Au:S/C:C/I:C/A:P) Published Feb 12, 2026 Added Feb 12, 2026 Modified Feb 13, 2026 Description MUNGE is an authentication service for creating and validating user credentials. From 0.5 to 0.5.17, local attacker can exploit a buffer overflow vulnerability in munged (the MUNGE authentication daemon) to leak cryptographic key material from process memory. With the leaked key material, the attacker could forge arbitrary MUNGE credentials to impersonate any user (including root) to services that rely on MUNGE for authentication. The vulnerability allows a buffer overflow by sending a crafted message with an oversized address length field, corrupting munged's internal state and enabling extraction of the MAC subkey used for credential verification. This vulnerability is fixed in 0.5.18. Solution debian-upgrade-munge References CVE-2026-25506 https://attackerkb.com/topics/CVE-2026-25506 CWE-787 DEBIAN-DLA-4477-1 DEBIAN-DSA-6129-1 NEW Explore Exposure Command Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.

Share this article