CVE-2024-22365

Name
CVE-2024-22365
Description
linux-pam (aka Linux PAM) before 1.6.0 allows attackers to cause a denial of service (blocked login process) via mkfifo because the openat call (for protect_dir) lacks O_DIRECTORY.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
cve@mitre.org http://www.openwall.com/lists/oss-security/2024/01/18/3
cve@mitre.org https://github.com/linux-pam/linux-pam
cve@mitre.org https://github.com/linux-pam/linux-pam/commit/031bb5a5d0d950253b68138b498dc93be69a64cb
cve@mitre.org https://github.com/linux-pam/linux-pam/releases/tag/v1.6.0

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:linux-pam:linux-pam:*:*:*:*:*:*:*:* linux-pam >= None < 1.6.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
linux-pam 3.19-main 1.5.3-r7 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
linux-pam 3.18-main 1.5.2-r10 Rasmus Thomsen <oss@cogitri.dev> possibly vulnerable
linux-pam 3.17-main 1.5.2-r1 Rasmus Thomsen <oss@cogitri.dev> possibly vulnerable
linux-pam 3.16-main 1.5.2-r0 Rasmus Thomsen <oss@cogitri.dev> possibly vulnerable
linux-pam edge-main 1.6.0-r0 Natanael Copa <ncopa@alpinelinux.org> fixed