Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-3032 http://linux.oracle.com/errata/ELSA-2026-3032.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: munge-0.5.13-3.el8_10.x86_64.rpm munge-devel-0.5.13-3.el8_10.i686.rpm munge-devel-0.5.13-3.el8_10.x86_64.rpm munge-libs-0.5.13-3.el8_10.i686.rpm munge-libs-0.5.13-3.el8_10.x86_64.rpm aarch64: munge-0.5.13-3.el8_10.aarch64.rpm munge-devel-0.5.13-3.el8_10.aarch64.rpm munge-libs-0.5.13-3.el8_10.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates/munge-0.5.13-3.el8_10.src.rpm Related CVEs: CVE-2026-25506 Description of changes: [0.5.13-3] - Fix CVE-2026-25506 - Resolves: RHEL-148521 _______________________________________________ El-errata mailing list
Important: munge security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:3033", "synopsis": "Important: munge security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for munge.\nThis update affects Rocky Linux 10.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "MUNGE (MUNGE Uid 'N' Gid Emporium) is an authentication service for creating and validating credentials. It is designed to be highly scalable for use in an HPC cluster environment. It allows a process to authenticate the UID and GID of another local or remote process within a group of hosts having common users and groups. These hosts form a security realm that is defined by a shared cryptographic key. Clients within this security realm can create and validate credentials without the use of root privileges, reserved ports, or platform-specific methods.\n\nSecurity Fix(es):\n\n* MUNGE: MUNGE has a buffer overflow in message unpacking allows key leakage and credential forgery (CVE-2026-25506)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 10"], "fixes": [{"ticket": "2438715", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2438715", "description": ""}], "cves": [{"name": "CVE-2026-25506", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2026-25506", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L", "cvss3BaseScore": "7.7", "cwe": "CWE-120"}], "references": [], "publishedAt": "2026-02-24T18:56:34.668877Z", "rpms": {"Rocky Linux 10": {"nvras": ["munge-libs-0:0.5.15-11.el10_1.aarch64.rpm", "munge-debuginfo-0:0.5.15-11.el10_1.aarch64.rpm", "munge-debuginfo-0:0.5.15-11.el10_1.s390x.rpm","munge-devel-0:0.5.15-11.el10_1.x86_64.rpm", "munge-debugsource-0:0.5.15-11.el10_1.aarch64.rpm", "munge-libs-0:0.5.15-11.el10_1.ppc64le.rpm", "munge-devel-0:0.5.15-11.el10_1.s390x.rpm", "munge-0:0.5.15-11.el10_1.s390x.rpm", "munge-debugsource-0:0.5.15-11.el10_1.x86_64.rpm", "munge-debugsource-0:0.5.15-11.el10_1.ppc64le.rpm", "munge-libs-0:0.5.15-11.el10_1.x86_64.rpm", "munge-0:0.5.15-11.el10_1.src.rpm", "munge-libs-0:0.5.15-11.el10_1.s390x.rpm", "munge-libs-debuginfo-0:0.5.15-11.el10_1.aarch64.rpm", "munge-debugsource-0:0.5.15-11.el10_1.s390x.rpm", "munge-0:0.5.15-11.el10_1.ppc64le.rpm", "munge-libs-debuginfo-0:0.5.15-11.el10_1.ppc64le.rpm", "munge-0:0.5.15-11.el10_1.x86_64.rpm", "munge-debuginfo-0:0.5.15-11.el10_1.ppc64le.rpm", "munge-libs-debuginfo-0:0.5.15-11.el10_1.x86_64.rpm", "munge-devel-0:0.5.15-11.el10_1.aarch64.rpm", "munge-libs-debuginfo-0:0.5.15-11.el10_1.s390x.rpm", "munge-0:0.5.15-11.el10_1.aarch64.rpm", "munge-debuginfo-0:0.5.15-11.el10_1.x86_64.rpm", "munge-devel-0:0.5.15-11.el10_1.ppc64le.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. MUNGE security update for Rocky Linux addresses critical buffer overflow issue allowing credential forgery. Stay safe!. MUNGE update. . Severity: Important. LinuxSecurity.com Team
Important: munge security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:3034", "synopsis": "Important: munge security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for munge.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "MUNGE (MUNGE Uid 'N' Gid Emporium) is an authentication service for creating and validating credentials. It is designed to be highly scalable for use in an HPC cluster environment. It allows a process to authenticate the UID and GID of another local or remote process within a group of hosts having common users and groups. These hosts form a security realm that is defined by a shared cryptographic key. Clients within this security realm can create and validate credentials without the use of root privileges, reserved ports, or platform-specific methods.\n\nSecurity Fix(es):\n\n* MUNGE: MUNGE has a buffer overflow in message unpacking allows key leakage and credential forgery (CVE-2026-25506)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2438715", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2438715", "description": ""}], "cves": [{"name": "CVE-2026-25506", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2026-25506", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L", "cvss3BaseScore": "7.7", "cwe": "CWE-120"}], "references": [], "publishedAt": "2026-02-24T18:54:11.875441Z", "rpms": {"Rocky Linux 9": {"nvras": ["munge-0:0.5.13-14.el9_7.aarch64.rpm", "munge-0:0.5.13-14.el9_7.ppc64le.rpm", "munge-0:0.5.13-14.el9_7.s390x.rpm", "munge-0:0.5.13-14.el9_7.src.rpm","munge-0:0.5.13-14.el9_7.x86_64.rpm", "munge-debuginfo-0:0.5.13-14.el9_7.aarch64.rpm", "munge-debuginfo-0:0.5.13-14.el9_7.i686.rpm", "munge-debuginfo-0:0.5.13-14.el9_7.ppc64le.rpm", "munge-debuginfo-0:0.5.13-14.el9_7.s390x.rpm", "munge-debuginfo-0:0.5.13-14.el9_7.x86_64.rpm", "munge-debugsource-0:0.5.13-14.el9_7.aarch64.rpm", "munge-debugsource-0:0.5.13-14.el9_7.i686.rpm", "munge-debugsource-0:0.5.13-14.el9_7.ppc64le.rpm", "munge-debugsource-0:0.5.13-14.el9_7.s390x.rpm", "munge-debugsource-0:0.5.13-14.el9_7.x86_64.rpm", "munge-devel-0:0.5.13-14.el9_7.aarch64.rpm", "munge-devel-0:0.5.13-14.el9_7.i686.rpm", "munge-devel-0:0.5.13-14.el9_7.ppc64le.rpm", "munge-devel-0:0.5.13-14.el9_7.s390x.rpm", "munge-devel-0:0.5.13-14.el9_7.x86_64.rpm", "munge-libs-0:0.5.13-14.el9_7.aarch64.rpm", "munge-libs-0:0.5.13-14.el9_7.i686.rpm", "munge-libs-0:0.5.13-14.el9_7.ppc64le.rpm", "munge-libs-0:0.5.13-14.el9_7.s390x.rpm", "munge-libs-0:0.5.13-14.el9_7.x86_64.rpm", "munge-libs-debuginfo-0:0.5.13-14.el9_7.aarch64.rpm", "munge-libs-debuginfo-0:0.5.13-14.el9_7.i686.rpm", "munge-libs-debuginfo-0:0.5.13-14.el9_7.ppc64le.rpm", "munge-libs-debuginfo-0:0.5.13-14.el9_7.s390x.rpm", "munge-libs-debuginfo-0:0.5.13-14.el9_7.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Important Munge security update for Rocky Linux 9 addresses key leakage, ensuring secure authentication. Read for details.. Munge Security Update, Rocky Linux Important Patch, Credential Forgery Fix, Buffer Overflow Resolution. . Severity: Important. LinuxSecurity.com Team
Important: munge security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:3032", "synopsis": "Important: munge security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for munge.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "MUNGE (MUNGE Uid 'N' Gid Emporium) is an authentication service for creating and validating credentials. It is designed to be highly scalable for use in an HPC cluster environment. It allows a process to authenticate the UID and GID of another local or remote process within a group of hosts having common users and groups. These hosts form a security realm that is defined by a shared cryptographic key. Clients within this security realm can create and validate credentials without the use of root privileges, reserved ports, or platform-specific methods.\n\nSecurity Fix(es):\n\n* MUNGE: MUNGE has a buffer overflow in message unpacking allows key leakage and credential forgery (CVE-2026-25506)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2438715", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2438715", "description": ""}], "cves": [{"name": "CVE-2026-25506", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2026-25506", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L", "cvss3BaseScore": "7.7", "cwe": "CWE-120"}], "references": [], "publishedAt": "2026-02-24T18:52:02.882818Z", "rpms": {"Rocky Linux 8": {"nvras": ["munge-0:0.5.13-3.el8_10.aarch64.rpm", "munge-0:0.5.13-3.el8_10.src.rpm", "munge-0:0.5.13-3.el8_10.x86_64.rpm", "munge-debuginfo-0:0.5.13-3.el8_10.aarch64.rpm","munge-debuginfo-0:0.5.13-3.el8_10.i686.rpm", "munge-debuginfo-0:0.5.13-3.el8_10.x86_64.rpm", "munge-debugsource-0:0.5.13-3.el8_10.aarch64.rpm", "munge-debugsource-0:0.5.13-3.el8_10.i686.rpm", "munge-debugsource-0:0.5.13-3.el8_10.x86_64.rpm", "munge-devel-0:0.5.13-3.el8_10.aarch64.rpm", "munge-devel-0:0.5.13-3.el8_10.i686.rpm", "munge-devel-0:0.5.13-3.el8_10.x86_64.rpm", "munge-libs-0:0.5.13-3.el8_10.aarch64.rpm", "munge-libs-0:0.5.13-3.el8_10.i686.rpm", "munge-libs-0:0.5.13-3.el8_10.x86_64.rpm", "munge-libs-debuginfo-0:0.5.13-3.el8_10.aarch64.rpm", "munge-libs-debuginfo-0:0.5.13-3.el8_10.i686.rpm", "munge-libs-debuginfo-0:0.5.13-3.el8_10.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Munge security update for Rocky Linux 8 addresses an important buffer overflow risk affecting credential integrity.. Munge Update Rocky Linux Important Buffer Overflow Credential Forgery. . Severity: Important. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-3033 http://linux.oracle.com/errata/ELSA-2026-3033.html The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network: x86_64: munge-0.5.15-11.el10_1.x86_64.rpm munge-devel-0.5.15-11.el10_1.x86_64.rpm munge-libs-0.5.15-11.el10_1.x86_64.rpm aarch64: munge-0.5.15-11.el10_1.aarch64.rpm munge-devel-0.5.15-11.el10_1.aarch64.rpm munge-libs-0.5.15-11.el10_1.aarch64.rpm SRPMS: http://oss.oracle.com/ol10/SRPMS-updates/munge-0.5.15-11.el10_1.src.rpm Related CVEs: CVE-2026-25506 Description of changes: [0.5.15-11] - Fix CVE-2026-25506 _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-3034 http://linux.oracle.com/errata/ELSA-2026-3034.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: munge-0.5.13-14.0.1.el9_7.x86_64.rpm munge-devel-0.5.13-14.0.1.el9_7.i686.rpm munge-devel-0.5.13-14.0.1.el9_7.x86_64.rpm munge-libs-0.5.13-14.0.1.el9_7.i686.rpm munge-libs-0.5.13-14.0.1.el9_7.x86_64.rpm aarch64: munge-0.5.13-14.0.1.el9_7.aarch64.rpm munge-devel-0.5.13-14.0.1.el9_7.aarch64.rpm munge-libs-0.5.13-14.0.1.el9_7.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates/munge-0.5.13-14.0.1.el9_7.src.rpm Related CVEs: CVE-2026-25506 Description of changes: [0.5.13-14.0.1] - Updated path for removal of unneeded init file [0.5.13-14] - Fix CVE-2026-25506 - Resolved: RHEL-148533 _______________________________________________ El-errata mailing list
An update that solves one vulnerability can now be installed.. # Security update for munge Announcement ID: SUSE-SU-2026:0484-1 Release Date: 2026-02-12T18:22:47Z Rating: important References: * bsc#1257651 Cross-References: * CVE-2026-25506 CVSS scores: * CVE-2026-25506 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L * CVE-2026-25506 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS An update that solves one vulnerability can now be installed. ## Description: This update for munge fixes the following issues: * CVE-2026-25506: buffer overflow in message unpacking (bsc#1257651). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-484=1 openSUSE-SLE-15.6-2026-484=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-484=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * libmunge2-debuginfo-0.5.15-150600.25.6.1 * munge-debuginfo-0.5.15-150600.25.6.1 * munge-0.5.15-150600.25.6.1 * munge-debugsource-0.5.15-150600.25.6.1 * libmunge2-0.5.15-150600.25.6.1 * munge-devel-0.5.15-150600.25.6.1 * openSUSE Leap 15.6 (x86_64) * munge-devel-32bit-0.5.15-150600.25.6.1 * libmunge2-32bit-debuginfo-0.5.15-150600.25.6.1 * libmunge2-32bit-0.5.15-150600.25.6.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libmunge2-64bit-debuginfo-0.5.15-150600.25.6.1 * libmunge2-64bit-0.5.15-150600.25.6.1 * munge-devel-64bit-0.5.15-150600.25.6.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 x86_64) * libmunge2-debuginfo-0.5.15-150600.25.6.1 * munge-debuginfo-0.5.15-150600.25.6.1 *munge-0.5.15-150600.25.6.1 * munge-debugsource-0.5.15-150600.25.6.1 * libmunge2-0.5.15-150600.25.6.1 * munge-devel-0.5.15-150600.25.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-25506.html * https://bugzilla.suse.com/show_bug.cgi?id=1257651 . Important security update for munge addresses a buffer overflow issue on openSUSE. Immediate installation recommended for users.. openSUSE munge buffer overflow patch. . Severity: Important. LinuxSecurity.com Team
MUNGE could be made to crash or run programs as your login if it opened a specially crafted file.. ========================================================================== Ubuntu Security Notice USN-8040-1 February 12, 2026 munge vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: MUNGE could be made to crash or run programs as your login if it opened a specially crafted file. Software Description: - munge: authentication service for credentials Details: Titouan Lazard discovered that MUNGE contained an exploitable buffer overflow in munged (the MUNGE authentication daemon). A local attacker could possibly use this issue to forge MUNGE credentials, leading to arbitrary code execution. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 libmunge-dev 0.5.16-1ubuntu0.1 libmunge2 0.5.16-1ubuntu0.1 munge 0.5.16-1ubuntu0.1 Ubuntu 24.04 LTS libmunge-dev 0.5.15-4ubuntu0.1 libmunge2 0.5.15-4ubuntu0.1 munge 0.5.15-4ubuntu0.1 Ubuntu 22.04 LTS libmunge-dev 0.5.14-6ubuntu0.1 libmunge2 0.5.14-6ubuntu0.1 munge 0.5.14-6ubuntu0.1 Ubuntu 20.04 LTS libmunge-dev 0.5.13-2ubuntu0.1~esm1 Available with Ubuntu Pro libmunge2 0.5.13-2ubuntu0.1~esm1 Available with Ubuntu Pro munge 0.5.13-2ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS libmunge-dev 0.5.13-1ubuntu0.1~esm1 Available with Ubuntu Pro libmunge2 0.5.13-1ubuntu0.1~esm1 Available with Ubuntu Pro munge 0.5.13-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS libmunge-dev 0.5.11-3ubuntu0.1+esm1 Available with Ubuntu Pro libmunge2 0.5.11-3ubuntu0.1+esm1 Available with Ubuntu Pro munge 0.5.11-3ubuntu0.1+esm1 Available with Ubuntu Pro Ubuntu 14.04 LTS libmunge-dev 0.5.11-1ubuntu1.1+esm1 Available with Ubuntu Pro libmunge2 0.5.11-1ubuntu1.1+esm1 Available with Ubuntu Pro munge 0.5.11-1ubuntu1.1+esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8040-1 CVE-2026-25506 Package Information: https://launchpad.net/ubuntu/+source/munge/0.5.15-4ubuntu0.1 . Critical security issue in MUNGE could lead to system crashes or unauthorized program execution.. MUNGE security update, Ubuntu buffer overflow, critical vulnerability, authentication service, security advisory. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.