yocto ▾
›
scarthgap ▾
›
vulnerability
›
CVE-2024-22365
Component Overview
Vulnerability Overview
Name
CVE-2024-22365
Source
NVD (
link
)
Debian (
link
)
Description
linux-pam (aka Linux PAM) before 1.6.0 allows attackers to cause a denial of service (blocked login process) via mkfifo because the openat call (for protect_dir) lacks O_DIRECTORY.
CWEs
CWE-664
Published Date
Feb 6, 2024
Updated Date
Jun 17, 2026
Workaround
-
Advisories
http://www.openwall.com/lists/oss-security/2024/01/18/3
Exploit
https://github.com/linux-pam/linux-pam
Product
https://github.com/linux-pam/linux-pam/commit/031bb5a5d0d950253b68138b498dc93be69a64cb
Patch
https://github.com/linux-pam/linux-pam/releases/tag/v1.6.0
Release Notes
http://www.openwall.com/lists/oss-security/2024/01/18/3
Exploit
https://github.com/linux-pam/linux-pam
Product
https://github.com/linux-pam/linux-pam/commit/031bb5a5d0d950253b68138b498dc93be69a64cb
Patch
https://github.com/linux-pam/linux-pam/releases/tag/v1.6.0
Release Notes
Analysis
#
Affected Component
Analysis
libpam
Patched
Vulnerability Ratings
#
5.5
CVSSv31
5.5
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
linux-pam
buildroot
2025.02.x
1.6.1
Not Affected
linux-pam
buildroot
master
1.7.2
Not Affected
libpam
openwrt
master
1.7.1-r5
Not Affected
libpam
openwrt
openwrt-25.12
1.7.1-r5
Not Affected
libpam
yocto
kirkstone
1.5.2
Patched
libpam
yocto
master
1.7.2
Not Affected
Resolved with patches
#
libpam (yocto:kirkstone)
#
Title
Author
Resolve
1
pam_namespace: protect_dir(): use O_DIRECTORY to prevent
Matthias Gerstner <matthias.gerstner@suse.de>
CVE-2024-22365
libpam (yocto:scarthgap)
#
Title
Author
Resolve
1
pam_namespace: protect_dir(): use O_DIRECTORY to prevent
Matthias Gerstner <matthias.gerstner@suse.de>
CVE-2024-22365