CVE-2024-22365Improper Control of a Resource Through its Lifetime in Linux-pam

Severity
5.5MEDIUMNVD
EPSS
0.1%
top 64.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 6
Latest updateMar 26

Description

linux-pam (aka Linux PAM) before 1.6.0 allows attackers to cause a denial of service (blocked login process) via mkfifo because the openat call (for protect_dir) lacks O_DIRECTORY.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Patches

🔴Vulnerability Details

2
GHSA
GHSA-pcmw-6hxc-hqmx: linux-pam (aka Linux PAM) before 12024-02-06
OSV
CVE-2024-22365: linux-pam (aka Linux PAM) before 12024-02-06

📋Vendor Advisories

5
Ubuntu
PAM vulnerability2024-03-26
Microsoft
linux-pam (aka Linux PAM) before 1.6.0 allows attackers to cause a denial of service (blocked login process) via mkfifo because the openat call (for protect_dir) lacks O_DIRECTORY.2024-02-13
Red Hat
pam: allowing unprivileged user to block another user namespace2024-01-18
Ubuntu
PAM vulnerability2024-01-17
Debian
CVE-2024-22365: pam - linux-pam (aka Linux PAM) before 1.6.0 allows attackers to cause a denial of ser...2024
CVE-2024-22365 — Linux-pam vulnerability | cvebase