Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Fedora 43 munge 0.5.18 Critical Buffer Overflow CVE-2026-25506

fedora
Calendar Grey February 26, 2026
Dist Fedora Esm H88
MUNGE 0.5.18 update in Fedora 43 addresses critical buffer overflow issues affecting credential integrity.
Update to 0.5.18, resolve CVE-2026-25506

Summary

MUNGE (MUNGE Uid 'N' Gid Emporium) is an authentication service for creating

and validating credentials. It is designed to be highly scalable for use

in an HPC cluster environment.

It allows a process to authenticate the UID and GID of another local or

remote process within a group of hosts having common users and groups.

These hosts form a security realm that is defined by a shared cryptographic

key. Clients within this security realm can create and validate credentials

without the use of root privileges, reserved ports, or platform-specific

methods.

Update Information:

Update to 0.5.18, resolve CVE-2026-25506

Change Log

* Fri Feb 13 2026 Michal Schmidt - 0.5.18-1 - Update to 0.5.18 * Fri Jan 16 2026 Fedora Release Engineering - 0.5.16-7 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild

References


[ 1 ] Bug #2414773 - munge-0.5.18 is available https://bugzilla.redhat.com/show_bug.cgi?id=2414773 [ 2 ] Bug #2438833 - CVE-2026-25506 munge: MUNGE has a buffer overflow in message unpacking allows key leakage and credential forgery [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2438833

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-ec8baadd48' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: munge
Product: Fedora 43
Version: 0.5.18
Release: 1.fc43
Summary: Enables uid & gid authentication across a host cluster

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here