CVE-2023-4641: Red Hat Codeready Linux Builder

Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.

A flaw was found in shadow-utils. When asking for a new password, shadow-utils asks the password twice. If the password fails on the second attempt, shadow-utils fails in cleaning the buffer used to store the first entry. This may allow an attacker with enough access to retrieve the password from the memory.

Affected products

  • Red Hat Codeready Linux Builder: version 8.0 only; version 9.0 only
  • Red Hat Codeready Linux Builder For ARM64: version 8.0_aarch64 only; version 9.0_aarch64 only
  • Red Hat Codeready Linux Builder For IBM Z Systems: version 8.0_s390x only; version 9.0_s390x only
  • Red Hat Codeready Linux Builder For Power Little Endian: version 8.0_ppc64le only; version 9.0_ppc64le only
  • Red Hat Enterprise Linux: version 8.0 only; version 9.0 only
  • Red Hat Enterprise Linux For Arm 64: version 8.0 only; version 9.0 only
  • Red Hat Enterprise Linux For IBM Z Systems: version 8.0_s390x only; version 9.0_s390x only
  • Red Hat Enterprise Linux For Power Little Endian: version 8.0_ppc64le only; version 9.0_ppc64le only
  • Shadow-Maint Shadow-Utils: before 4.14.0 (fixed in 4.14.0)

Published 2023-12-27. Last modified 2026-06-17.