Medium severity5.9NVD Advisory· Published Jun 14, 2026· Updated Aug 10, 2026
CVE-2026-54411
CVE-2026-54411
Description
Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
9- osv-coords7 versionspkg:rpm/almalinux/pam-develpkg:rpm/opensuse/pam-full-src&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/pam&distro=openSUSE%20Tumbleweedpkg:rpm/almalinux/pam-libspkg:rpm/almalinux/pam-docspkg:rpm/almalinux/pampkg:rpm/opensuse/pam&distro=openSUSE%20Leap%2016.0
< 1.3.1-40.el8_10+ 6 more
- (no CPE)range: < 1.3.1-40.el8_10
- (no CPE)range: < 1.7.1-160000.5.1
- (no CPE)range: < 1.7.2+git12-2.1
- (no CPE)range: < 1.6.1-9.el10_2.1
- (no CPE)range: < 1.5.1-28.el9_8.1
- (no CPE)range: < 1.3.1-40.el8_10
- (no CPE)range: < 1.7.1-160000.5.1
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.