DEBIAN-CVE-2026-54411

Source
https://security-tracker.debian.org/tracker/CVE-2026-54411
Import Source
https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-54411.json
JSON Data
https://api.test.osv.dev/v1/vulns/DEBIAN-CVE-2026-54411
Upstream
Published
2026-06-14T18:17:20Z
Modified
2026-09-01T16:06:50Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X CVSS Calculator
Summary
[none]
Details

Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences.

References

Affected packages

Debian:12 / pam

Package

Name
pam
Purl
pkg:deb/debian/pam?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.5.2-6
1.5.2-6+deb12u1
1.5.2-6+deb12u2
1.5.2-7
1.5.2-8
1.5.2-9
1.5.2-9.1
1.5.3-1
1.5.3-2
1.5.3-3
1.5.3-4
1.5.3-5
1.5.3-6
1.5.3-6+hurd.1
1.5.3-7
1.7.0-1
1.7.0-2
1.7.0-2+hurd.1
1.7.0-3
1.7.0-4
1.7.0-5
1.7.0-6
1.7.0-7
1.7.0-8

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-54411.json"

Debian:13 / pam

Package

Name
pam
Purl
pkg:deb/debian/pam?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.7.0-5
1.7.0-6
1.7.0-7
1.7.0-8

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-54411.json"

Debian:14 / pam

Package

Name
pam
Purl
pkg:deb/debian/pam?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.7.0-5
1.7.0-6
1.7.0-7
1.7.0-8

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-54411.json"