Database/Kernel, userspace & hypervisor
shadow-utils: Possible password leak during passwd(1) change (uninitialised memory)
CVSS 4.7CVE-2023-4641Kernel, userspace & hypervisorcurated
Impact
Possible password leak during passwd(1) change (uninitialised memory)
Who can reach it
Local user
What to do
Package update; no reboot
References
Related entries
- Linux kernel (net/xfrm): The 32-bit compat translation of xfrm netlink attributes uses the attacker-supplied attributeCVE-2023-52746 · Linux kernel (net/xfrm)Medium
- Intel CPU (Native BHI): Native Branch History Injection - unprivileged user leaks kernel memory despite eIBRSCVE-2024-2201 · Intel CPU (Native BHI)Medium
- Linux kernel (drivers/vfio/pci): A failed interrupt-context allocation while enabling INTx leaks the IRQ name string.CVE-2024-38632 · Linux kernel (drivers/vfio/pci)Medium
- Linux kernel (drivers/iommu): Removing a device from the per-IOMMU page-fault queue responds to outstanding faults butCVE-2025-21770 · Linux kernel (drivers/iommu)Medium
- Linux kernel (drivers/pci/controller): The Intel VMD driver guarded config-space access with a lock type that becomes aCVE-2025-23161 · Linux kernel (drivers/pci/controller)Medium
- Linux kernel (ksmbd): Use-after-free in ksmbd session logoff (found by an LLM-assisted audit)CVE-2025-37899 · Linux kernel (ksmbd)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.