Executive brief
A security flaw exists in a core Linux utility used for managing user logins. An attacker could potentially bypass certain security rules that restrict access based on where a user is connecting from. This could allow unauthorized access to systems that rely on specific network location rules for security.
Technical details
A vulnerability exists in the login(1) utility of util-linux due to improper hostname canonicalization when invoked with the -h option. The utility may modify the supplied remote hostname before setting the PAM_RHOST variable. An attacker can exploit this by providing a specially crafted hostname to bypass Pluggable Authentication Module (PAM) access control rules (such as pam_access) that rely on Fully Qualified Domain Names (FQDNs). Exploitation requires a remote login pathway that invokes login(1) with -h and a target system configured with host-based authorization rules. Red Hat has released updates for affected Hardened Images.
Affected products
- kernel.org util-linux All versions prior to fix
- Red Hat Red Hat Hardened Images util-linux-main prior to 2.42-7.1.hum1
Timeline
- 2026-02-25: other: Vulnerability reported to Red Hat Bugzilla
- 2026-04-03: disclosed: Initial public disclosure
- 2026-04-09: patched: Red Hat released security advisory RHSA-2026:7180