Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-3184

25
FAUCET Score

CVE-2026-3184 identifies a flaw in the util-linux login(1) utility where improper hostname canonicalization, when invoked with the -h option, can modify the supplied remote hostname before setting PAM_RHOST. This vulnerability, rated CVSS 3.7 LOW with high attack complexity, allows a remote attacker to provide a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access controls and leading to unauthorized access. There is currently no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB, though it has received some community discussion and media coverage primarily related to vendor security updates.

Impacted Technologies

VendorProductVersion(s)CPE
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:kernel:util-linux:-:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:redhat:hardened_images:-:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

3.7LOW

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
2.2
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.44%
Probability of exploitation in next 30 days
EPSS Percentile
35.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0044 is in the 22nd percentile among its peer group of 23,705 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

microsoftpatch availablevia msrc
Product: cbl2 util-linux 2.37.4-10 on CBL Mariner 2.0Fixed in: 2.37.4-11
microsoftpatch availablevia msrc
Product: azl3 util-linux 2.40.2-3 on Azure Linux 3.0Fixed in: 2.40.2-4
microsoftpatch availablevia msrc
Product: azl3 util-linux 2.40.2-4 on Azure Linux 3.0Fixed in: 2.40.2-4
microsoftpatch availablevia msrc
Product: 20786-17086Fixed in: 2.37.4-11
microsoftpatch availablevia msrc
Product: 20804-17084Fixed in: 2.40.2-4
microsoftpatch availablevia msrc
Product: 21213-17084Fixed in: 2.40.2-4

Vendor Advisories (2)

microsoft2026-Apr/CVE-2026-3184Low

Util-linux: util-linux: access control bypass due to improper hostname canonicalization

Apr 2, 2026
redhatCVE-2026-3184Low

util-linux: util-linux: Access control bypass due to improper hostname canonicalization

Feb 25, 2026

References

access.redhat.com / errata/RHSA-2026:7180
Third Party Advisory
access.redhat.com / security/cve/CVE-2026-3184
Third Party Advisory
bugzilla.redhat.com / show_bug.cgi
Issue TrackingThird Party Advisory