CVE-2024-10041

Published Oct 23, 2024

Last updated a year ago

Overview

Description
A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This flaw could result in leaked passwords, such as those found in /etc/shadow while performing authentications.
Source
secalert@redhat.com
NVD status
Modified
Products
linux-pam

Risk scores

CVSS 3.1

Type
Secondary
Base score
4.7
Impact score
3.6
Exploitability score
1
Vector string
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Severity
MEDIUM

Weaknesses

secalert@redhat.com
CWE-922
nvd@nist.gov
NVD-CWE-noinfo
134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-922

Social media

Hype score
Not currently trending
  1. ๐Ÿšจ #SUSE Security Update: Patch for CVE-2024-10041 is live for SLE Server 12 SP5. Fixes a mod-severity vuln AND a CPU performance regression. Affected products & patch commands. Read more:๐Ÿ‘‰ https://t.co/VM8GKj5ZEs #Security https://t.co/t0iZ31m

    @Cezar_H_Linux

    26 Aug 2025

    36 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. ๐Ÿšจ #SUSE Security Update Alert! ๐Ÿšจ Patch CVE-2024-10041 in PAM and fix a CPU performance regression. A 2-in-1 update for: โœ… Security โœ… Performance Affects: #SUSE LES 15 SP6/SP7, #openSUSE Leap 15.6, MicroOS. Read more: ๐Ÿ‘‰ https://t.co/A3DFTUw1qr #Security https://t.co/

    @Cezar_H_Linux

    26 Aug 2025

    69 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  3. ๐Ÿš€ Critical #LinuxSecurity Update! openSUSE 15.4 patches CVE-2024-10041 in AppArmorโ€”fixes shadow file access bugs. Read more: ๐Ÿ‘‰ https://t.co/A0iacnMKQ5 #SysAdmin #CyberSecurity https://

    @Cezar_H_Linux

    14 May 2025

    36 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. โš ๏ธ Critical PAM flaw in Gentoo Linux (CVE-2024-10041)! Password leakage risk โ€“ patch immediately: emerge ">=sys-libs/pam-1.7.0_p20241230" Read more: ๐Ÿ‘‰https://t.co/lPZh7A4I50 #InfoSec #LinuxAdmin #CyberThreat https://t.co/rtabDBsiwY

    @Cezar_H_Linux

    12 May 2025

    30 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. โš ๏ธ SUSE Linux users! CVE-2024-10041 (CVSS 5.7) allows shadow file leaks if unpatched. Fix: zypper in -t patch SUSE-2025-1511=1 Details: ๐Ÿ‘‰https://t.co/7qMUo6ja7P #InfoSec #Linux https://t.co/uyaBlVmuNL

    @Cezar_H_Linux

    9 May 2025

    15 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. ๐Ÿšจ SUSE issues critical patch for CVE-2024-10041 (CVSS 5.7)! Affects AppArmor in Leap 15.5, SLE, and HPC. Fix: zypper in -t patch SUSE-2025-1512=1 Read more: https://t.co/tntrgLG7IA ๐Ÿ‘‰ #SUSE #Security https://t.co/qOwasGjcfm

    @Cezar_H_Linux

    9 May 2025

    21 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. ๐Ÿšจ CVE-2024-10041 (Published: 2024-10-23) affects Red Hat products. Ensure your systems are updated to the latest versions to mitigate exploitation risks. For detailed remediation steps, visit: https://t.co/S40GdxDdIG. Stay secure! ๐Ÿ”’ #CyberSecurity #RedHat

    @transilienceai

    27 Oct 2024

    21 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. ๐Ÿšจ CVE-2024-10041 (Published: 2024-10-23) affects Red Hat products. This vulnerability impacts specific versions, allowing potential exploitation. Ensure your systems are updated to the latest patches to mitigate risks. For detailed remediation steps, visit:โ€ฆ https://t.co/FiHxCSO

    @transilienceai

    27 Oct 2024

    12 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. ๐Ÿšจ CVE-2024-10041 (Published: 2024-10-23) affects Red Hat products. This vulnerability impacts specific versions, allowing potential exploitation. To safeguard your systems, ensure you apply the latest patches and updates. For detailed remediation steps, visit:โ€ฆ https://t.co/5Gyt

    @transilienceai

    26 Oct 2024

    8 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. CVE-2024-10041 A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to itโ€ฆ https://t.co/z20HAJTyXH

    @CVEnew

    23 Oct 2024

    316 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations