Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb modules plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences.
Two separate operations in a product require different amounts of time to complete, in a way that is observable to an actor and reveals security-relevant information about the state of the product, such as whether a particular operation was successful or not.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Red Hat Hardened Images | RedHat | pam-main-1.7.2-2.2.hum1 | * |
| Red Hat Hardened Images | RedHat | pam-main-1.7.2-1.1.hum1 | * |
| Pam | Ubuntu | devel | * |
| Pam | Ubuntu | jammy | * |
| Pam | Ubuntu | noble | * |
| Pam | Ubuntu | questing | * |
| Pam | Ubuntu | resolute | * |