Database/Kernel, userspace & hypervisor
PAM (pam-config): Local user is treated as `allow_active` in PAM
CVE-2025-6018Kernel, userspace & hypervisorcurated
Impact
Local user is treated as allow_active in PAM - first half of a public unprivileged-to-root chain on SUSE/openSUSE
Who can reach it
Local user (SSH session counts)
What to do
Package update; no reboot. Chain with CVE-2025-6019 - patch both or neither is meaningful
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.