CVE-2026-54411
Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences.
- Published Jun 14, 2026
- CVSS 6.9 medium
- 0.5% chance of exploitation in the next 30 days (EPSS)
Affected software
In the news
- Multiple vulnerabilities in IBM products CERT-FR ·