CVE-2026-54411EPSS p40.7%
CVE-2026-54411CVE-2026-54411
Description
Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences.
Scoring
| CVSS | 5.9 () |
| Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
| EPSS | 0.50% probability of exploitation · percentile 40.7% · 2026-10-05T12:00:23Z |
| Last modified | 2026-08-10 |