suse · CVE-2023-4641

Quick triage

Priority: low Published: 2023-08-31 23:19:11 UTC Updated: 2026-04-20 08:41:44 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2023-4641 severity low: SUSE including 352 source package names (1.1.2-2.10:libsubid5-4.17.2-150600.17.18.1, 1.1.2-2.10:login_defs-4.17.2-150600.17.18.1, …), 766 product×package rows across 266 product lines (Container bci/bci-init, Container bci/bci-sle15-kernel-module-devel, … (266 product lines)): Fixed 586, Known Affected 180.

Description:

A flaw was found in shadow-utils. When asking for a new password, shadow-utils asks the password twice. If the password fails on the second attempt, shadow-utils fails in cleaning the buffer used to store the first entry. This may allow an attacker with enough access to retrieve the password from the memory.

cvelogic Threat Intelligence