Логотип exploitDog
bind:"CVE-2026-25506"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2026-25506"

Количество 15

Количество 15

ubuntu логотип

CVE-2026-25506

около 2 месяцев назад

MUNGE is an authentication service for creating and validating user credentials. From 0.5 to 0.5.17, local attacker can exploit a buffer overflow vulnerability in munged (the MUNGE authentication daemon) to leak cryptographic key material from process memory. With the leaked key material, the attacker could forge arbitrary MUNGE credentials to impersonate any user (including root) to services that rely on MUNGE for authentication. The vulnerability allows a buffer overflow by sending a crafted message with an oversized address length field, corrupting munged's internal state and enabling extraction of the MAC subkey used for credential verification. This vulnerability is fixed in 0.5.18.

CVSS3: 7.7
EPSS: Низкий
redhat логотип

CVE-2026-25506

около 2 месяцев назад

MUNGE is an authentication service for creating and validating user credentials. From 0.5 to 0.5.17, local attacker can exploit a buffer overflow vulnerability in munged (the MUNGE authentication daemon) to leak cryptographic key material from process memory. With the leaked key material, the attacker could forge arbitrary MUNGE credentials to impersonate any user (including root) to services that rely on MUNGE for authentication. The vulnerability allows a buffer overflow by sending a crafted message with an oversized address length field, corrupting munged's internal state and enabling extraction of the MAC subkey used for credential verification. This vulnerability is fixed in 0.5.18.

CVSS3: 7.7
EPSS: Низкий
nvd логотип

CVE-2026-25506

около 2 месяцев назад

MUNGE is an authentication service for creating and validating user credentials. From 0.5 to 0.5.17, local attacker can exploit a buffer overflow vulnerability in munged (the MUNGE authentication daemon) to leak cryptographic key material from process memory. With the leaked key material, the attacker could forge arbitrary MUNGE credentials to impersonate any user (including root) to services that rely on MUNGE for authentication. The vulnerability allows a buffer overflow by sending a crafted message with an oversized address length field, corrupting munged's internal state and enabling extraction of the MAC subkey used for credential verification. This vulnerability is fixed in 0.5.18.

CVSS3: 7.7
EPSS: Низкий
debian логотип

CVE-2026-25506

около 2 месяцев назад

MUNGE is an authentication service for creating and validating user cr ...

CVSS3: 7.7
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0484-1

около 1 месяца назад

Security update for munge

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0451-1

около 2 месяцев назад

Security update for munge

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0450-1

около 2 месяцев назад

Security update for munge

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0448-1

около 2 месяцев назад

Security update for munge

EPSS: Низкий
rocky логотип

RLSA-2026:3034

около 1 месяца назад

Important: munge security update

EPSS: Низкий
rocky логотип

RLSA-2026:3033

около 1 месяца назад

Important: munge security update

EPSS: Низкий
rocky логотип

RLSA-2026:3032

около 1 месяца назад

Important: munge security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-3034

около 1 месяца назад

ELSA-2026-3034: munge security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-3033

около 1 месяца назад

ELSA-2026-3033: munge security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-3032

около 1 месяца назад

ELSA-2026-3032: munge security update (IMPORTANT)

EPSS: Низкий
fstec логотип

BDU:2026-01902

около 2 месяцев назад

Уязвимость демона munged сервиса аутентификации MUNGE, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации и повысить свои привилегии до уровня root

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-25506

MUNGE is an authentication service for creating and validating user credentials. From 0.5 to 0.5.17, local attacker can exploit a buffer overflow vulnerability in munged (the MUNGE authentication daemon) to leak cryptographic key material from process memory. With the leaked key material, the attacker could forge arbitrary MUNGE credentials to impersonate any user (including root) to services that rely on MUNGE for authentication. The vulnerability allows a buffer overflow by sending a crafted message with an oversized address length field, corrupting munged's internal state and enabling extraction of the MAC subkey used for credential verification. This vulnerability is fixed in 0.5.18.

CVSS3: 7.7
0%
Низкий
около 2 месяцев назад
redhat логотип
CVE-2026-25506

MUNGE is an authentication service for creating and validating user credentials. From 0.5 to 0.5.17, local attacker can exploit a buffer overflow vulnerability in munged (the MUNGE authentication daemon) to leak cryptographic key material from process memory. With the leaked key material, the attacker could forge arbitrary MUNGE credentials to impersonate any user (including root) to services that rely on MUNGE for authentication. The vulnerability allows a buffer overflow by sending a crafted message with an oversized address length field, corrupting munged's internal state and enabling extraction of the MAC subkey used for credential verification. This vulnerability is fixed in 0.5.18.

CVSS3: 7.7
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-25506

MUNGE is an authentication service for creating and validating user credentials. From 0.5 to 0.5.17, local attacker can exploit a buffer overflow vulnerability in munged (the MUNGE authentication daemon) to leak cryptographic key material from process memory. With the leaked key material, the attacker could forge arbitrary MUNGE credentials to impersonate any user (including root) to services that rely on MUNGE for authentication. The vulnerability allows a buffer overflow by sending a crafted message with an oversized address length field, corrupting munged's internal state and enabling extraction of the MAC subkey used for credential verification. This vulnerability is fixed in 0.5.18.

CVSS3: 7.7
0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2026-25506

MUNGE is an authentication service for creating and validating user cr ...

CVSS3: 7.7
0%
Низкий
около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:0484-1

Security update for munge

0%
Низкий
около 1 месяца назад
suse-cvrf логотип
SUSE-SU-2026:0451-1

Security update for munge

0%
Низкий
около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:0450-1

Security update for munge

0%
Низкий
около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:0448-1

Security update for munge

0%
Низкий
около 2 месяцев назад
rocky логотип
RLSA-2026:3034

Important: munge security update

0%
Низкий
около 1 месяца назад
rocky логотип
RLSA-2026:3033

Important: munge security update

0%
Низкий
около 1 месяца назад
rocky логотип
RLSA-2026:3032

Important: munge security update

0%
Низкий
около 1 месяца назад
oracle-oval логотип
ELSA-2026-3034

ELSA-2026-3034: munge security update (IMPORTANT)

около 1 месяца назад
oracle-oval логотип
ELSA-2026-3033

ELSA-2026-3033: munge security update (IMPORTANT)

около 1 месяца назад
oracle-oval логотип
ELSA-2026-3032

ELSA-2026-3032: munge security update (IMPORTANT)

около 1 месяца назад
fstec логотип
BDU:2026-01902

Уязвимость демона munged сервиса аутентификации MUNGE, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации и повысить свои привилегии до уровня root

CVSS3: 7.8
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу