Skip to content

(3.0.0‐3.14.1) Privilege escalation on MUNGE caused by CVE‐2026‐25506

Giacomo Marciani edited this page Feb 12, 2026 · 2 revisions

The issue

MUNGE is the service responsible for authenticating communications in Slurm clusters. All versions from 0.5 to 0.5.17 are affected by CVE-2026-25506. This vulnerability allows local users to trigger a buffer overflow in munged's message unpacking code, leaking the cryptographic key from process memory. With that key, attackers can forge credentials to impersonate any user (including root)—on Slurm clusters, this should be treated as a local-root exploit.

Affected ParallelCluster versions, OSes and schedulers

All ParallelCluster versions on all OSes when using the Slurm scheduler are impacted.

Mitigation

The vulnerability is fixed in MUNGE 0.5.18. To mitigate, you have the following options:

  1. Upgrade ParallelCluster and recreate the cluster: if you are able to recreate your cluster, create a new cluster using ParallelCluster 3.14.2 or later when available, which ships the fixed MUNGE version.
  2. Patch MUNGE in place: if you cannot recreate your cluster, patch MUNGE on the head node and on compute nodes via AMI patching. If building a new AMI is not an option or requires time, hot patching can be applied. Detailed instructions for both options are provided here.

Clone this wiki locally