CVE-2024-22365 is a denial-of-service vulnerability affecting Linux PAM (linux-pam) versions prior to 1.6.0. It allows a local attacker to block login processes by exploiting a missing O_DIRECTORY flag in an openat call related to mkfifo. With a CVSS score of 5.5 (Medium), this vulnerability requires local access and low privileges, but does not involve user interaction, leading to high availability impact. Currently, there is no known active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.6.0CPE matchmatch criteria | cpe:2.3:a:linux-pam:linux-pam:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2024-22365
Nov 12, 2024HP ThinPro 8.0 SP 9 Security Updates
Jun 17, 2024HP ThinPro 8.0 SP 9 Security Updates
Jun 17, 2024HP ThinPro 8.1 SP 2 Security Updates
Apr 12, 2024HP ThinPro 8.1 SP 2 Security Updates
Apr 12, 2024linux-pam (aka Linux PAM) before 1.6.0 allows attackers to cause a denial of service (blocked login process) via mkfifo because the openat call (for protect_dir) lacks O_DIRECTORY.
Feb 13, 2024pam: allowing unprivileged user to block another user namespace
Jan 18, 2024