CVE-2026-54411

1 karet z 1 položek · v celém archivu · celý přehled CZ · EN/orig

CVE-2026-54411

EPSS 0.00

Hodnocení závažnosti

6.9 CVSS 4.0 TuranSec existuje proof-of-concept

útok odkudkoli z internetu nutné obejít ochrany jen v určitém nastavení nebo načasování bez přihlášení bez zásahu uživatele
dopad plný únik dat beze změny dat bez výpadku
přesah bez úniku v okolních systémech beze změny v okolních systémech bez výpadku v okolních systémech
vydavatel dodává nelze automatizovat roztroušená data

CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/AU:N/V:D

5.9 CVSS 3.1 TuranSec

útok odkudkoli z internetu útok vyžaduje přípravu bez přihlášení bez zásahu uživatele
dopad plný únik dat beze změny dat bez výpadku
přesah dopad jen na zranitelnou součást

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

zvyšuje závažnost mírně zvyšuje závažnost snižuje závažnost

1

CVE-2026-54411 Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences. The comparison uses strncmp() (or strncasecmp() when PAM_ICASE_ARG is set) preceded by a length-equality check, so the time to reject a candidate depends on the index of the first differing byte and on whether the candidate's length matches the stored password, leaking the password length and individual prefix bytes. The vulnerable path is reached when the administrator configures pam_userdb with crypt=none, with an unrecognized crypt method, or without a crypt= argument, causing the module to store and compare credentials in plaintext.

Information published.

EPSS 0.00 CVE-2026-54411 Linux-PAM US

Microsoft Security ·