TROYANOSYVIRUS
Back to CVEs

CVE-2026-25506

HIGH
7.7

Description

MUNGE is an authentication service for creating and validating user credentials. From 0.5 to 0.5.17, local attacker can exploit a buffer overflow vulnerability in munged (the MUNGE authentication daemon) to leak cryptographic key material from process memory. With the leaked key material, the attacker could forge arbitrary MUNGE credentials to impersonate any user (including root) to services that rely on MUNGE for authentication. The vulnerability allows a buffer overflow by sending a crafted message with an oversized address length field, corrupting munged's internal state and enabling extraction of the MAC subkey used for credential verification. This vulnerability is fixed in 0.5.18.

CVE Details

CVSS v3.1 Score7.7
SeverityHIGH
CVSS VectorCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L
Attack VectorLOCAL
ComplexityHIGH
Privileges RequiredLOW
User InteractionNONE
Published2/10/2026
Last Modified2/25/2026
Sourcenvd
Honeypot Sightings0

Affected Products

debian:debian_linuxopensuse:munge

Weaknesses (CWE)

CWE-787

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.