[CLSA-2026:1772571803] munge: Fix of CVE-2026-25506
Type:
security
Severity:
Important
Release date:
2026-03-03 21:03:28 UTC
Description:
- CVE-2026-25506: fix buffer overflow in message parsing and add bounds checks and input validation for address length; prevent leak of cryptographic MAC subkey and forging of arbitrary credentials
Updated packages:
  • munge-0.5.13-13.el9_2.tuxcare.els1.x86_64.rpm
    sha:618c75855d7cbc2263988e2ba663d385145096f13114b5d37241b445dfbb2592
  • munge-devel-0.5.13-13.el9_2.tuxcare.els1.i686.rpm
    sha:8ee2fa6eb42ed9cc7b41f4496095941ea60f9cf9ca986a375bf43cfa8d6dc2a1
  • munge-devel-0.5.13-13.el9_2.tuxcare.els1.x86_64.rpm
    sha:79a8eb38d6cb4c04ea1fb79961692592e9c19faa2c738c0b0dc3a983f90ab3e1
  • munge-libs-0.5.13-13.el9_2.tuxcare.els1.i686.rpm
    sha:ab0df88f13402b35511911d1515f59f12a507b48bda7bf01f43cdebd15a74f5a
  • munge-libs-0.5.13-13.el9_2.tuxcare.els1.x86_64.rpm
    sha:033689533d5194ef3592bdb0c24f21fb86eb3ae6384bc2d8a51c9437ad3a3b5f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.