Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pamuserdb module's plaintext-password comparison path in modules/pamuserdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences.