Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Linux Pam

First CVE: Mar 12, 2009Active for: 17 yearsTotal CVEs: 37

Linux PAM is the pluggable authentication module framework that mediates user authentication across Unix and Linux systems, providing a narrow but foundational component to the operating system authentication layer. Despite its focused scope, the project sits prominently in the vulnerability landscape due to its role in authentication gating for virtually all user-facing access on Linux deployments. Defenders should treat PAM updates as part of their system-hardening baseline, as flaws in authentication infrastructure propagate broadly; current CVE counts, severity, and exposure details are shown alongside this summary.

FAUCET AI Generated
19
Total CVEs
More Total CVEs than 96% of tracked vendors
2.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 89% of tracked vendors
5.5
Avg CVSS Score
Higher Avg CVSS Score than 22% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Linux Pam over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 12, 2009
17 years ago
Most Recent CVE
Jun 14, 2026
40 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (19 CVEs).

19 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-28321CRITICAL
The Linux-PAM package before 1.5.2-6.1 for openSUSE Tumbleweed allows authentication bypass for SSH logins. The pam_access.so module doesn't correctly restrict login if a user trie
Sep 19, 20229.830NONO
CVE-2026-54411MEDIUM
Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that al
Jun 14, 20265.929NONO
CVE-2020-27780CRITICAL
A flaw was found in Linux-Pam in versions prior to 1.5.1 in the way it handle empty passwords for non-existing users. When the user doesn't exist PAM try to authenticate with root
Dec 18, 20209.829NONO
CVE-2010-3853MEDIUM
pam_namespace.c in the pam_namespace module in Linux-PAM (aka pam) before 1.1.3 uses the environment of the invoking application or service during execution of the namespace.init s
Jan 24, 20116.921NONO
CVE-2024-10041MEDIUM
A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard inp
Oct 23, 20244.720NONO
CVE-2024-22365MEDIUM
linux-pam (aka Linux PAM) before 1.6.0 allows attackers to cause a denial of service (blocked login process) via mkfifo because the openat call (for protect_dir) lacks O_DIRECTORY.
Feb 6, 20245.519NONO
CVE-2015-3238MEDIUM
The _unix_run_helper_binary function in the pam_unix module in Linux-PAM (aka pam) before 1.2.1, when unable to directly access passwords, allows local users to enumerate usernames
Aug 24, 20156.519NONO
CVE-2009-0887MEDIUM
Integer signedness error in the _pam_StrTok function in libpam/pam_misc.c in Linux-PAM (aka pam) 1.0.3 and earlier, when a configuration file contains non-ASCII usernames, might al
Mar 12, 20096.619NONO
CVE-2010-4708HIGH
The pam_env module in Linux-PAM (aka pam) 1.1.2 and earlier reads the .pam_environment file in a user's home directory, which might allow local users to run programs with an uninte
Jan 24, 20117.218NONO
CVE-2014-2583MEDIUM
Multiple directory traversal vulnerabilities in pam_timestamp.c in the pam_timestamp module for Linux-PAM (aka pam) 1.1.8 allow local users to create arbitrary files or possibly by
Apr 10, 20145.817NONO
View all 19 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products19 CVEs
16%
68%
11%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (10.5%)
Network4 (21.1%)
Unknown13 (68.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (21.1%)
High2 (10.5%)
Unknown13 (68.4%)
User Interaction
None6 (31.6%)
Unknown13 (68.4%)
Required0 (0.0%)
Privileges Required
Low2 (10.5%)
High0 (0.0%)
None4 (21.1%)
Unknown13 (68.4%)

Exploit Exposure

Signals from CVEs in this vendor scope (19 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Linux Pam.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Linux Pam — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Linux Pam's Products

View all 3 CNAs →

Top CWEs