A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Suse | — | Upgrade libblkid1Upgrade libuuid-develUpgrade util-linux-tty-toolsUpgrade uuiddUpgrade python-libmountUpgrade libsmartcols1Upgrade libsmartcols-devel-staticUpgrade liblastlog2-2Upgrade libmount-devel-staticUpgrade libfdisk-devel-staticUpgrade python313-libmountUpgrade lastlog2Upgrade libblkid1-32bitUpgrade libsmartcols1-32bitUpgrade liblastlog2-develUpgrade util-linuxUpgrade libuuid-devel-32bitUpgrade libmount-devel-32bitUpgrade libblkid-devel-32bitUpgrade util-linux-extraUpgrade libsmartcols-devel-32bitUpgrade libuuid-devel-staticUpgrade libuuid1-32bitUpgrade libmount-develUpgrade libfdisk-develUpgrade libblkid-develUpgrade libuuid1Upgrade libsmartcols-develUpgrade util-linux-systemdUpgrade libfdisk1-32bitUpgrade libmount1Upgrade libfdisk1Upgrade libfdisk-devel-32bitUpgrade libblkid-devel-staticUpgrade libmount1-32bitUpgrade util-linux-langUpgrade python3-libmount | Mar 10, 2026 | Mar 4, 2026 |
| Ubuntu | — | Upgrade util-linux | Aug 31, 2026 | Apr 3, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jun 22, 2026 | Apr 3, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub