CVE Vulnerabilities

CVE-2024-22365

Published: Feb 06, 2024 | Modified: Feb 14, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
5.5 MODERATE
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM

linux-pam (aka Linux PAM) before 1.6.0 allows attackers to cause a denial of service (blocked login process) via mkfifo because the openat call (for protect_dir) lacks O_DIRECTORY.

Affected Software

Name Vendor Start Version End Version
Linux-pam Linux-pam * 1.6.0 (excluding)
Red Hat Enterprise Linux 8 RedHat pam-0:1.3.1-33.el8 *
Red Hat Enterprise Linux 9 RedHat pam-0:1.5.1-19.el9 *
Red Hat Enterprise Linux 9 RedHat pam-0:1.5.1-19.el9 *
Pam Ubuntu bionic *
Pam Ubuntu devel *
Pam Ubuntu esm-infra/bionic *
Pam Ubuntu esm-infra/xenial *
Pam Ubuntu focal *
Pam Ubuntu jammy *
Pam Ubuntu lunar *
Pam Ubuntu mantic *
Pam Ubuntu trusty *
Pam Ubuntu trusty/esm *
Pam Ubuntu xenial *

References