🛡️ AZL-77444 — munge
Description
CVE-2026-25506 affecting package munge for versions less than 0.5.18-1
MUNGE is an authentication service for creating and validating user credentials. From 0.5 to 0.5.17, local attacker can exploit a buffer overflow vulnerability in munged (the MUNGE authentication daemon) to leak cryptographic key material from process memory. With the leaked key material, the attacker could forge arbitrary MUNGE credentials to impersonate any user (including root) to services that rely on MUNGE for authentication. The vulnerability allows a buffer overflow by sending a crafted message with an oversized address length field, corrupting munged's internal state and enabling extraction of the MAC subkey used for credential verification. This vulnerability is fixed in 0.5.18.
Affected software
AZL-77444 is recorded against 1 package.
- munge (fixed in 0.5.18-1)
Timeline and source
Published on 10 February 2026 and last revised on 21 April 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| munge | — | 0.5.18-1 |
References
Similar Threats
- Unknown CLSA-2026-1772571803
- Unknown CLSA-2026-1772572505
- Unknown ALSA-2026:3032
- Unknown ALSA-2026:3033
- Unknown ALSA-2026:3034
More AZL 7 advisories
Browse all of AZL 7 in the advisory index.
Free Vulnerability Check
Is your site affected by AZL-77444?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against AZL-77444 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.