CVE detail
CVE-2026-25506
MUNGE is an authentication service for creating and validating user credentials. From 0.5 to 0.5.17, local attacker can exploit a buffer overflow vulnerability in munged (the MUNGE authentication daemon) to leak cryptographic key material from process memory. With the leaked key material, the attacker could forge arbitrary MUNGE credentials to impersonate any user (including root) to services that rely on MUNGE for authentication. The vulnerability allows a buffer overflow by sending a crafted message with an oversized address length field, corrupting munged's internal state and enabling extraction of the MAC subkey used for credential verification. This vulnerability is fixed in 0.5.18.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 16.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
22 source links · newest first
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25506.jsonsecurity.access.redhat.com
No excerpt available.
Vendor Advisorysecurity.access.redhat.comFeb 10, 2026, 7:16 PM - https://bugzilla.redhat.com/show_bug.cgi?id=2438715bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comFeb 10, 2026, 7:16 PM - https://access.redhat.com/security/cve/CVE-2026-25506access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comFeb 10, 2026, 7:16 PM - https://access.redhat.com/errata/RHSA-2026:3034access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comFeb 10, 2026, 7:16 PM - https://access.redhat.com/errata/RHSA-2026:3033access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comFeb 10, 2026, 7:16 PM - https://access.redhat.com/errata/RHSA-2026:3032access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comFeb 10, 2026, 7:16 PM - https://access.redhat.com/errata/RHSA-2026:3013access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comFeb 10, 2026, 7:16 PM - https://access.redhat.com/errata/RHSA-2026:3012access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comFeb 10, 2026, 7:16 PM - https://access.redhat.com/errata/RHSA-2026:3011access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comFeb 10, 2026, 7:16 PM - https://access.redhat.com/errata/RHSA-2026:3010access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comFeb 10, 2026, 7:16 PM - https://access.redhat.com/errata/RHSA-2026:2954access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comFeb 10, 2026, 7:16 PM - https://access.redhat.com/errata/RHSA-2026:2949access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comFeb 10, 2026, 7:16 PM - https://access.redhat.com/errata/RHSA-2026:2934access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comFeb 10, 2026, 7:16 PM - https://access.redhat.com/errata/RHSA-2026:2923access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comFeb 10, 2026, 7:16 PM - https://access.redhat.com/errata/RHSA-2026:2918access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comFeb 10, 2026, 7:16 PM - https://access.redhat.com/errata/RHSA-2026:16174access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comFeb 10, 2026, 7:16 PM No excerpt available.
Vendor Advisorylists.debian.orgFeb 10, 2026, 7:16 PM- http://www.openwall.com/lists/oss-security/2026/02/17/6www.openwall.com
No excerpt available.
Exploitwww.openwall.comFeb 10, 2026, 7:16 PM - http://www.openwall.com/lists/oss-security/2026/02/10/3www.openwall.com
No excerpt available.
Exploitwww.openwall.comFeb 10, 2026, 7:16 PM No excerpt available.
Exploitgithub.comFeb 10, 2026, 7:16 PMNo excerpt available.
Exploitgithub.comFeb 10, 2026, 7:16 PMNo excerpt available.
Exploitgithub.comFeb 10, 2026, 7:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2022-36280CVSS 6.3 · Medium
An out-of-bounds(OOB) memory access vulnerability was found in vmwgfx driver in drivers/gpu/vmxgfx/vmxgfx_kms.c in GPU component in the Linux kernel with device file '/dev/dri/ren…
- CVE-2021-4214CVSS 5.5 · Medium
A heap overflow flaw was found in libpngs' pngimage.c program. This flaw allows an attacker with local network access to pass a specially crafted PNG file to the pngimage utility,…
- CVE-2022-37434CVSS 9.8 · Critical
zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetH…
- CVE-2022-31031CVSS 9.8 · Critical
PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In version…
- CVE-2022-24764CVSS 7.5 · High
PJSIP is a free and open source multimedia communication library written in C. Versions 2.12 and prior contain a stack buffer overflow vulnerability that affects PJSUA2 users or u…
- CVE-2020-27823CVSS 7.8 · High
A flaw was found in OpenJPEG’s encoder. This flaw allows an attacker to pass specially crafted x,y offset input to OpenJPEG to use during encoding. The highest threat from this vu…