PT-2022-4982 · Linux Pam+2 · Linux-Pam+2
Thomas Leroy
·
Published
2022-03-29
·
Updated
2025-05-29
·
CVE-2022-28321
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Linux-PAM versions prior to 1.5.2-6.1
Description
The issue is related to the pam access.so module of the Linux-PAM package, which does not correctly restrict login if a user tries to connect from an IP address that is not resolvable via DNS. This can allow a user with denied access to a machine to still get access. The relevance of this issue is largely limited to openSUSE Tumbleweed and openSUSE Factory, and it does not affect Linux-PAM upstream.
Recommendations
For Linux-PAM versions prior to 1.5.2-6.1, update to version 1.5.2-6.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the pam access.so module until a patch is available. Avoid using the pam access.so module for SSH logins from IP addresses that are not resolvable via DNS until the issue is resolved.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Linux-Pam
Ubuntu