RHSA-2026:60224: Moderate: pam security update
Moderate: pam security update
Other sources
Pluggable Authentication Modules (PAM) provide a system to set up authentication policies without the need to recompile programs to handle authentication.Security Fix(es): linux-pam: Plaintext password recovery via timing discrepancy in pamuserdb module (CVE-2026-54411) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/pamto a version that resolves this vulnerability.Fixed in 1.5.1-27.el9_8.1 - Upgrade
Upgrade
redhat/pam-debuginfoto a version that resolves this vulnerability.Fixed in 1.5.1-27.el9_8.1 - Upgrade
Upgrade
redhat/pam-debugsourceto a version that resolves this vulnerability.Fixed in 1.5.1-27.el9_8.1 - Upgrade
Upgrade
redhat/pam-develto a version that resolves this vulnerability.Fixed in 1.5.1-27.el9_8.1 - Upgrade
Upgrade
redhat/pam-docsto a version that resolves this vulnerability.Fixed in 1.5.1-27.el9_8.1 - Upgrade
Upgrade
redhat/pamto a version that resolves this vulnerability.Fixed in 1.5.1-27.el9_8.1.aa - Upgrade
Upgrade
redhat/pam-debuginfoto a version that resolves this vulnerability.Fixed in 1.5.1-27.el9_8.1.aa - Upgrade
Upgrade
redhat/pam-debugsourceto a version that resolves this vulnerability.Fixed in 1.5.1-27.el9_8.1.aa - Upgrade
Upgrade
redhat/pam-develto a version that resolves this vulnerability.Fixed in 1.5.1-27.el9_8.1.aa - Upgrade
Upgrade
redhat/pam-docsto a version that resolves this vulnerability.Fixed in 1.5.1-27.el9_8.1.aa
Event History
Frequently Asked Questions
What information could an attacker recover through this issue?
The issue allows plaintext password recovery through a timing discrepancy in the pam_userdb module.
Which component needs to be present for this issue to be relevant?
The affected component identified in the advisory is the pam_userdb module in PAM. The provided data does not state which PAM configurations enable or use this module.
Which Red Hat packages are listed in the advisory?
The advisory lists redhat/pam, redhat/pam-debuginfo, redhat/pam-debugsource, redhat/pam-devel, and redhat/pam-docs, along with specified Red Hat Enterprise Linux offerings.