CVE-2024-22365
MEDIUMDescription
linux-pam (aka Linux PAM) before 1.6.0 allows attackers to cause a denial of service (blocked login process) via mkfifo because the openat call (for protect_dir) lacks O_DIRECTORY.
Is your site exposed to CVE-2024-22365?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| linux-pam | linux-pam |
References
Advisories & Patches
Exploits
Other References
Frequently Asked Questions
What is CVE-2024-22365? +
How severe is CVE-2024-22365? +
What products are affected by CVE-2024-22365? +
How do I check if I'm vulnerable to CVE-2024-22365? +
Related Vulnerabilities
OpenPLC Runtime v3 contains an input validation flaw in the /upload-program-action endpoint: the epoch_time field supplied during program uploads is …
Object lifecycle issue in WebShare in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker who convinced a …
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has …
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a …
The attacker can use the raft server protocol in an unauthenticated way. The attacker can see the server's resources, including …
Resource reuse vulnerability in the GPU module. Successful exploitation of this vulnerability may affect service confidentiality.