CVE-2026-54411

ADVISORY - nist

Summary

Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences.

EPSS Score: 0.00333 (0.259)

Common Weakness Enumeration (CWE)

ADVISORY - nist

Observable Timing Discrepancy


Sign in to Docker Scout

See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.

Sign in