CVE-2018-17953: Kernel Linux-Pam

High severity, CVSS 8.1. EPSS: 1.3% chance of exploitation in the next 30 days.

A incorrect variable in a SUSE specific patch for pam_access rule matching in PAM 1.3.0 in openSUSE Leap 15.0 and SUSE Linux Enterprise 15 could lead to pam_access rules not being applied (fail open).

Affected products

  • Kernel Linux-Pam: version 1.3.0 only

Published 2018-11-27. Last modified 2026-06-17.