Junglewise Threat Intelligence

CVE-2026-25506: MUNGE buffer overflow in munged message unpacking

CVE-2026-25506 · Severity: high · CVSS 7.7 · Published 2026-02-10

Technologies: Debian Linux. Vendors: Debian, Opensuse.

Executive brief

MUNGE is an authentication service used primarily in High-Performance Computing (HPC) environments to create and validate user credentials. A security flaw allows a local user to corrupt the authentication daemon's memory and steal secret cryptographic keys. With these keys, an attacker can forge credentials to impersonate any user, including root, potentially gaining full control over the cluster or services relying on MUNGE.

Technical details

A buffer overflow vulnerability exists in the `_msg_unpack()` function within `src/libcommon/m_msg.c` of the MUNGE authentication daemon (munged). The vulnerability is triggered when unpacking a `MUNGE_MSG_DEC_RSP` message where the `addr_len` field (an untrusted `uint8_t`) is not validated against the 4-byte `in_addr` structure size before a `_copy()` operation. A local attacker can connect to the munged Unix socket and send a crafted message with an oversized address length (up to 255), causing an out-of-bounds write that corrupts the daemon's internal state. This can be exploited to leak the `mac_key` and other secrets from process memory, enabling the forgery of arbitrary MUNGE credentials. The issue is fixed in version 0.5.18 by adding bounds checking.

Affected products

  • dun MUNGE 0.5 to 0.5.17

Timeline

  • 2026-02-10: disclosed: Vulnerability disclosed by maintainer Chris Dunlap and researcher Titouan Lazard.
  • 2026-02-10: patched: Fixed in MUNGE version 0.5.18.
  • 2026-02-10: advisory: GitHub Security Advisory GHSA-r9cr-jf4v-75gh published.

References

Related threats