Количество 15
Количество 15
CVE-2026-25506
MUNGE is an authentication service for creating and validating user credentials. From 0.5 to 0.5.17, local attacker can exploit a buffer overflow vulnerability in munged (the MUNGE authentication daemon) to leak cryptographic key material from process memory. With the leaked key material, the attacker could forge arbitrary MUNGE credentials to impersonate any user (including root) to services that rely on MUNGE for authentication. The vulnerability allows a buffer overflow by sending a crafted message with an oversized address length field, corrupting munged's internal state and enabling extraction of the MAC subkey used for credential verification. This vulnerability is fixed in 0.5.18.
CVE-2026-25506
MUNGE is an authentication service for creating and validating user credentials. From 0.5 to 0.5.17, local attacker can exploit a buffer overflow vulnerability in munged (the MUNGE authentication daemon) to leak cryptographic key material from process memory. With the leaked key material, the attacker could forge arbitrary MUNGE credentials to impersonate any user (including root) to services that rely on MUNGE for authentication. The vulnerability allows a buffer overflow by sending a crafted message with an oversized address length field, corrupting munged's internal state and enabling extraction of the MAC subkey used for credential verification. This vulnerability is fixed in 0.5.18.
CVE-2026-25506
MUNGE is an authentication service for creating and validating user credentials. From 0.5 to 0.5.17, local attacker can exploit a buffer overflow vulnerability in munged (the MUNGE authentication daemon) to leak cryptographic key material from process memory. With the leaked key material, the attacker could forge arbitrary MUNGE credentials to impersonate any user (including root) to services that rely on MUNGE for authentication. The vulnerability allows a buffer overflow by sending a crafted message with an oversized address length field, corrupting munged's internal state and enabling extraction of the MAC subkey used for credential verification. This vulnerability is fixed in 0.5.18.
CVE-2026-25506
MUNGE is an authentication service for creating and validating user cr ...
SUSE-SU-2026:0484-1
Security update for munge
SUSE-SU-2026:0451-1
Security update for munge
SUSE-SU-2026:0450-1
Security update for munge
SUSE-SU-2026:0448-1
Security update for munge
RLSA-2026:3034
Important: munge security update
RLSA-2026:3033
Important: munge security update
RLSA-2026:3032
Important: munge security update
ELSA-2026-3034
ELSA-2026-3034: munge security update (IMPORTANT)
ELSA-2026-3033
ELSA-2026-3033: munge security update (IMPORTANT)
ELSA-2026-3032
ELSA-2026-3032: munge security update (IMPORTANT)
BDU:2026-01902
Уязвимость демона munged сервиса аутентификации MUNGE, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации и повысить свои привилегии до уровня root
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-25506 MUNGE is an authentication service for creating and validating user credentials. From 0.5 to 0.5.17, local attacker can exploit a buffer overflow vulnerability in munged (the MUNGE authentication daemon) to leak cryptographic key material from process memory. With the leaked key material, the attacker could forge arbitrary MUNGE credentials to impersonate any user (including root) to services that rely on MUNGE for authentication. The vulnerability allows a buffer overflow by sending a crafted message with an oversized address length field, corrupting munged's internal state and enabling extraction of the MAC subkey used for credential verification. This vulnerability is fixed in 0.5.18. | CVSS3: 7.7 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-25506 MUNGE is an authentication service for creating and validating user credentials. From 0.5 to 0.5.17, local attacker can exploit a buffer overflow vulnerability in munged (the MUNGE authentication daemon) to leak cryptographic key material from process memory. With the leaked key material, the attacker could forge arbitrary MUNGE credentials to impersonate any user (including root) to services that rely on MUNGE for authentication. The vulnerability allows a buffer overflow by sending a crafted message with an oversized address length field, corrupting munged's internal state and enabling extraction of the MAC subkey used for credential verification. This vulnerability is fixed in 0.5.18. | CVSS3: 7.7 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-25506 MUNGE is an authentication service for creating and validating user credentials. From 0.5 to 0.5.17, local attacker can exploit a buffer overflow vulnerability in munged (the MUNGE authentication daemon) to leak cryptographic key material from process memory. With the leaked key material, the attacker could forge arbitrary MUNGE credentials to impersonate any user (including root) to services that rely on MUNGE for authentication. The vulnerability allows a buffer overflow by sending a crafted message with an oversized address length field, corrupting munged's internal state and enabling extraction of the MAC subkey used for credential verification. This vulnerability is fixed in 0.5.18. | CVSS3: 7.7 | 0% Низкий | около 2 месяцев назад | |
CVE-2026-25506 MUNGE is an authentication service for creating and validating user cr ... | CVSS3: 7.7 | 0% Низкий | около 2 месяцев назад | |
SUSE-SU-2026:0484-1 Security update for munge | 0% Низкий | около 1 месяца назад | ||
SUSE-SU-2026:0451-1 Security update for munge | 0% Низкий | около 2 месяцев назад | ||
SUSE-SU-2026:0450-1 Security update for munge | 0% Низкий | около 2 месяцев назад | ||
SUSE-SU-2026:0448-1 Security update for munge | 0% Низкий | около 2 месяцев назад | ||
RLSA-2026:3034 Important: munge security update | 0% Низкий | около 1 месяца назад | ||
RLSA-2026:3033 Important: munge security update | 0% Низкий | около 1 месяца назад | ||
RLSA-2026:3032 Important: munge security update | 0% Низкий | около 1 месяца назад | ||
ELSA-2026-3034 ELSA-2026-3034: munge security update (IMPORTANT) | около 1 месяца назад | |||
ELSA-2026-3033 ELSA-2026-3033: munge security update (IMPORTANT) | около 1 месяца назад | |||
ELSA-2026-3032 ELSA-2026-3032: munge security update (IMPORTANT) | около 1 месяца назад | |||
BDU:2026-01902 Уязвимость демона munged сервиса аутентификации MUNGE, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации и повысить свои привилегии до уровня root | CVSS3: 7.8 | 0% Низкий | около 2 месяцев назад |
Уязвимостей на страницу