• CVE-2024-10041

发布时间: 2025年6月6日

修改时间: 2025年6月6日

概要

A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This flaw could result in leaked passwords, such as those found in /etc/shadow while performing authentications.

CVSS v3 指标

NVD openEuler
Confidentiality High
Attack Vector Local
CVSS评分 N/A 4.7
Attack Complexity High
Privileges Required Low
Scope Unchanged
Integrity None
User Interaction None
Availability None

安全公告

公告名 概要 发布时间
KylinSec-SA-2025-2571 pam security update 2025年6月28日

影响产品

产品 状态
KY3.4-5 pam Fixed
V6 pam Fixed
KY3.5.3 pam Fixed