CVE-2026-3184 identifies a flaw in the util-linux login(1) utility where improper hostname canonicalization, when invoked with the -h option, can modify the supplied remote hostname before setting PAM_RHOST. This vulnerability, rated CVSS 3.7 LOW with high attack complexity, allows a remote attacker to provide a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access controls and leading to unauthorized access. There is currently no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB, though it has received some community discussion and media coverage primarily related to vendor security updates.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:kernel:util-linux:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:redhat:hardened_images:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.