Fedora Account System
Red Hat Associate
Red Hat Customer
Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences. The comparison uses strncmp() (or strncasecmp() when PAM_ICASE_ARG is set) preceded by a length-equality check, so the time to reject a candidate depends on the index of the first differing byte and on whether the candidate's length matches the stored password, leaking the password length and individual prefix bytes. The vulnerable path is reached when the administrator configures pam_userdb with crypt=none, with an unrecognized crypt method, or without a crypt= argument, causing the module to store and compare credentials in plaintext.
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:56131 https://access.redhat.com/errata/RHSA-2026:56131
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:59379 https://access.redhat.com/errata/RHSA-2026:59379
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:60224 https://access.redhat.com/errata/RHSA-2026:60224
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:61224 https://access.redhat.com/errata/RHSA-2026:61224
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:61229 https://access.redhat.com/errata/RHSA-2026:61229
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On Via RHSA-2026:61223 https://access.redhat.com/errata/RHSA-2026:61223
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:61225 https://access.redhat.com/errata/RHSA-2026:61225
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:61226 https://access.redhat.com/errata/RHSA-2026:61226
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2026:61227 https://access.redhat.com/errata/RHSA-2026:61227
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions Via RHSA-2026:61228 https://access.redhat.com/errata/RHSA-2026:61228
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:61230 https://access.redhat.com/errata/RHSA-2026:61230