linux-pam (aka Linux PAM) before 1.6.0 allows attackers to cause a denial of service (blocked login process) via mkfifo because the openat call (for protect_dir) lacks O_DIRECTORY.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Linux-pam | Linux-pam | * | 1.6.0 (excluding) |
Red Hat Enterprise Linux 8 | RedHat | pam-0:1.3.1-33.el8 | * |
Red Hat Enterprise Linux 9 | RedHat | pam-0:1.5.1-19.el9 | * |
Red Hat Enterprise Linux 9 | RedHat | pam-0:1.5.1-19.el9 | * |
Pam | Ubuntu | bionic | * |
Pam | Ubuntu | devel | * |
Pam | Ubuntu | esm-infra/bionic | * |
Pam | Ubuntu | esm-infra/xenial | * |
Pam | Ubuntu | focal | * |
Pam | Ubuntu | jammy | * |
Pam | Ubuntu | lunar | * |
Pam | Ubuntu | mantic | * |
Pam | Ubuntu | trusty | * |
Pam | Ubuntu | trusty/esm | * |
Pam | Ubuntu | xenial | * |