RHSA-2026:59379: Moderate: pam security update
Moderate: pam security update
Other sources
Pluggable Authentication Modules (PAM) provide a system to set up authentication policies without the need to recompile programs to handle authentication.Security Fix(es): linux-pam: Plaintext password recovery via timing discrepancy in pamuserdb module (CVE-2026-54411) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
Which systems are covered by this advisory?
The advisory applies to listed Red Hat Enterprise Linux offerings for Power little endian, ARM 64, and x86_64 Extended Life Cycle, including certain 4-year support, Extended Update Support, and Extended Life Cycle variants.
What component is being updated?
This is a security update for pam.
When was the advisory published and last modified?
It was published on 2026-08-25 and was last modified on 2026-08-25.