CVE-2026-3184

A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:kernel:util-linux:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:hardened_images:-:*:*:*:*:*:*:*

History

21 Jul 2026, 19:10

Type Values Removed Values Added
Summary
  • (es) Se encontró una falla en util-linux. La canonicalización incorrecta del nombre de host en la utilidad 'login(1)', cuando se invoca con la opción '-h', puede modificar el nombre de host remoto proporcionado antes de establecer 'PAM_RHOST'. Un atacante remoto podría explotar esto al proporcionar un nombre de host especialmente diseñado, eludiendo potencialmente las reglas de control de acceso de Módulos de Autenticación Conectables (PAM) basadas en host que dependen de nombres de dominio completamente calificados. Esto podría conducir a acceso no autorizado.

01 May 2026, 19:29

Type Values Removed Values Added
First Time Redhat
Kernel util-linux
Redhat hardened Images
Kernel
CPE cpe:2.3:a:redhat:hardened_images:-:*:*:*:*:*:*:*
cpe:2.3:a:kernel:util-linux:-:*:*:*:*:*:*:*
References () https://access.redhat.com/errata/RHSA-2026:7180 - () https://access.redhat.com/errata/RHSA-2026:7180 - Third Party Advisory
References () https://access.redhat.com/security/cve/CVE-2026-3184 - () https://access.redhat.com/security/cve/CVE-2026-3184 - Third Party Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2442570 - () https://bugzilla.redhat.com/show_bug.cgi?id=2442570 - Issue Tracking, Third Party Advisory

23 Apr 2026, 16:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:7180 -

03 Apr 2026, 19:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-03 19:17

Updated : 2026-07-21 19:10


NVD link : CVE-2026-3184

Mitre link : CVE-2026-3184

CVE.ORG link : CVE-2026-3184


JSON object : View

Products Affected

kernel

  • util-linux

redhat

  • hardened_images
CWE
CWE-289

Authentication Bypass by Alternate Name