Skip to content

(3.0.0-3.14.1) Privilege escalation on MUNGE caused by CVE-2026-25506 #7233

@gmarciani

Description

@gmarciani

The issue

MUNGE is the service responsible for authenticating communications in Slurm clusters. All versions from 0.5 to 0.5.17 are affected by CVE-2026-25506. This vulnerability allows local users to trigger a buffer overflow in munged's message unpacking code, leaking the cryptographic key from process memory. With that key, attackers can forge credentials to impersonate any user (including root)—on Slurm clusters, this should be treated as a local-root exploit.

Affected ParallelCluster versions, OSes and schedulers

All ParallelCluster versions on all OSes when using the Slurm scheduler are impacted.

Mitigation

You can find a detailed explanation and the mitigation of the problem here

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions