Alerts This Week
Warning Icon 1 1,229
Alerts This Week
Warning Icon 1 1,229

Debian 11 Munge Critical Buffer Overflow Threat DLA-4477-1 CVE-2026-25506

debian lts
Calendar Grey February 10, 2026
Dist Debian Esm H88
A critical security advisory detailing a buffer overflow issue in munge allowing credential forgery on Debian 11.
Titouan Lazard discovered a buffer overflow vulnerability in munge, an authentication service to create and validate credentials, which may allow local users to leak the MUNGE cryp...

Summary

Titouan Lazard discovered a buffer overflow vulnerability in munge, an
authentication service to create and validate credentials, which may
allow local users to leak the MUNGE cryptographic key and forge
arbitrary credentials.

Additional details can be found in the upstream advisory:
https://github.com/dun/munge/security/advisories/GHSA-r9cr-jf4v-75gh


For Debian 11 bullseye, this problem has been fixed in version
0.5.14-4+deb11u1.

We recommend that you upgrade your munge packages.

For the detailed security status of munge please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/munge

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS



Severity
critical
Lowest
Low
Medium
High
Critical

Package: munge
Version: 0.5.14-4+deb11u1
CVE ID: CVE-2026-25506

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here