Shadow-utils: possible password leak during passwd(1) change
Published Dec 27, 2023
5.5
MEDIUMCVSS 3.1
EPSS 0.26%
Description
A flaw was found in shadow-utils. When asking for a new password, shadow-utils asks the password twice. If the password fails on the second attempt, shadow-utils fails in cleaning the buffer used to store the first entry. This may allow an attacker with enough access to retrieve the password from the memory.
Affected products
No data.
Configuration 1
- < 4.14.0
Configuration 2
- 8.0
- 9.0
- 8.0_aarch64
- 9.0_aarch64
- 8.0_s390x
- 9.0_s390x
- 8.0_ppc64le
- 9.0_ppc64le
- 8.0
- 9.0
- 8.0
- 9.0
- 8.0_s390x
- 9.0_s390x
- 8.0_ppc64le
- 9.0_ppc64le
No data.
Red Hat Enterprise Linux 8
shadow-utils-2:4.6-19.el8
Fixed · RHSA-2023:7112
Red Hat Enterprise Linux 8.6 Extended Update Support
shadow-utils-2:4.6-17.el8_6
Fixed · RHSA-2024:0417
Red Hat Enterprise Linux 8.8 Extended Update Support
shadow-utils-2:4.6-17.el8_8.2
Fixed · RHSA-2024:2577
Red Hat Enterprise Linux 9
shadow-utils-2:4.9-8.el9
Fixed · RHSA-2023:6632
Red Hat Enterprise Linux 6
shadow-utils
Out of support scope
Red Hat Enterprise Linux 7
shadow-utils
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | shadow-utils-2:4.6-19.el8 | Fixed | RHSA-2023:7112 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | shadow-utils-2:4.6-17.el8_6 | Fixed | RHSA-2024:0417 |
| Red Hat Enterprise Linux 8.8 Extended Update Support | shadow-utils-2:4.6-17.el8_8.2 | Fixed | RHSA-2024:2577 |
| Red Hat Enterprise Linux 9 | shadow-utils-2:4.9-8.el9 | Fixed | RHSA-2023:6632 |
| Red Hat Enterprise Linux 6 | shadow-utils | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | shadow-utils | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This vulnerability is classified as low severity despite of confidentiality is high because it requires an attacker to have elevated access privileges to exploit the issue, an attacker must already have significant access to the system to retrieve the password from memory. Additionally, the issue is limited to specific scenarios where a password attempt fails, which reduces its overall risk.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
1 other source (Red Hat) ▾
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Jan 2, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2023–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (7 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.26% (0.00256) | 15.61th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.26% (0.00257) | 16.83th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.07% (0.00066) | 17.77th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00044) | 12.15th | v3 (v2023.03.01) |
| May 4, 2024 | 0.04% (0.00044) | 9.55th | v3 (v2023.03.01) |
| May 2, 2024 | 0.04% (0.00045) | 14.32th | v3 (v2023.03.01) |
| Dec 28, 2023 | 0.04% (0.00045) | 12.30th | v3 (v2023.03.01) |
References (9)
- https://access.redhat.com/errata/RHSA-2023:6632 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2023:7112 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2024:0417 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:2577 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2023-4641 vdb-entryx_refsource_REDHATThird Party AdvisoryVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2215945 issue-trackingx_refsource_REDHATIssue Tracking
- https://lists.debian.org/debian-lts-announce/2025/04/msg00026.html
- https://nvd.nist.gov/vuln/detail/CVE-2023-4641
- https://www.cve.org/CVERecord?id=CVE-2023-4641
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2023:6632 | vendor-advisoryx_refsource_REDHATThird Party Advisory | |
| https://access.redhat.com/errata/RHSA-2023:7112 | vendor-advisoryx_refsource_REDHATThird Party Advisory | |
| https://access.redhat.com/errata/RHSA-2024:0417 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/errata/RHSA-2024:2577 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/security/cve/CVE-2023-4641 | vdb-entryx_refsource_REDHATThird Party AdvisoryVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2215945 | issue-trackingx_refsource_REDHATIssue Tracking | |
| https://lists.debian.org/debian-lts-announce/2025/04/msg00026.html | ||
| https://nvd.nist.gov/vuln/detail/CVE-2023-4641 | ||
| https://www.cve.org/CVERecord?id=CVE-2023-4641 |
Change history (0)
No recorded changes yet.