- What: A security update addresses a buffer overflow vulnerability in munge, an authentication service.
- Impact: Local users could potentially leak the MUNGE cryptographic key and forge credentials.
- Affected: Debian 11 systems with the munge package installed.
- Patch: Update to version 0.5.14-4+deb11u1.
Debian dla-4477 : libmunge-dev - security update high Nessus Plugin ID 298586 Synopsis The remote Debian host is missing a security-related update. Description The remote Debian 11 host has packages installed that are affected by a vulnerability as referenced in the dla-4477 advisory. - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4477-1 [email protected] https://www.debian.org/lts/security/ Thorsten Alteholz February 10, 2026 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : munge Version : 0.5.14-4+deb11u1 CVE ID : CVE-2026-25506 Titouan Lazard discovered a buffer overflow vulnerability in munge, an authentication service to create and validate credentials, which may allow local users to leak the MUNGE cryptographic key and forge arbitrary credentials. Additional details can be found in the upstream advisory: https://github.com/dun/munge/security/advisories/GHSA-r9cr-jf4v-75gh For Debian 11 bullseye, this problem has been fixed in version 0.5.14-4+deb11u1. We recommend that you upgrade your munge packages. For the detailed security status of munge please refer to its security tracker page at: https://security-tracker.debian.org/tracker/munge Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS Tenable has extracted the preceding description block directly from the Debian security advisory. Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number. Solution Upgrade the libmunge-dev packages. See Also https://security-tracker.debian.org/tracker/source-package/munge https://security-tracker.debian.org/tracker/CVE-2026-25506 https://packages.debian.org/source/bullseye/munge Plugin Details Severity : High ID : 298586 File Name : debian_DLA-4477.nasl Version : 1.1 Type : local Agent : unix Family : Debian Local Security Checks Published : 2/10/2026 Updated : 2/10/2026 Supported Sensors : Agentless Assessment , Continuous Assessment , Frictionless Assessment Agent , Nessus Agent , Nessus Risk Information VPR Risk Factor : Critical Score : 9.2 CVSS v2 Risk Factor : Medium Base Score : 5.7 Temporal Score : 4.2 Vector : CVSS2#AV:L/AC:H/Au:S/C:C/I:C/A:P CVSS Score Source : CVE-2026-25506 CVSS v3 Risk Factor : High Base Score : 7.7 Temporal Score : 6.7 Vector : CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L Temporal Vector : CVSS:3.0/E:U/RL:O/RC:C Vulnerability Information CPE : p-cpe:/a:debian:debian_linux:munge , cpe:/o:debian:debian_linux:11.0 , p-cpe:/a:debian:debian_linux:libmunge-dev , p-cpe:/a:debian:debian_linux:libmunge2 Required KB Items : Host/local_checks_enabled , Host/Debian/release , Host/Debian/dpkg-l Exploit Ease : No known exploits are available Patch Publication Date : 2/10/2026 Vulnerability Publication Date : 2/10/2026 Reference Information CVE : CVE-2026-25506