CVE-2026-54411
ADVISORY - nistSummary
Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences.
EPSS Score: 0.00333 (0.259)
Common Weakness Enumeration (CWE)
ADVISORY - nist
Observable Timing Discrepancy
Sign in to Docker Scout
See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.
Sign in