-
Notifications
You must be signed in to change notification settings - Fork 314
(3.0.0‐3.14.1) Privilege escalation on MUNGE caused by CVE‐2026‐25506
Giacomo Marciani edited this page Feb 12, 2026
·
2 revisions
MUNGE is the service responsible for authenticating communications in Slurm clusters. All versions from 0.5 to 0.5.17 are affected by CVE-2026-25506. This vulnerability allows local users to trigger a buffer overflow in munged's message unpacking code, leaking the cryptographic key from process memory. With that key, attackers can forge credentials to impersonate any user (including root)—on Slurm clusters, this should be treated as a local-root exploit.
All ParallelCluster versions on all OSes when using the Slurm scheduler are impacted.
The vulnerability is fixed in MUNGE 0.5.18. To mitigate, you have the following options:
- Upgrade ParallelCluster and recreate the cluster: if you are able to recreate your cluster, create a new cluster using ParallelCluster 3.14.2 or later when available, which ships the fixed MUNGE version.
- Patch MUNGE in place: if you cannot recreate your cluster, patch MUNGE on the head node and on compute nodes via AMI patching. If building a new AMI is not an option or requires time, hot patching can be applied. Detailed instructions for both options are provided here.