RHSA-2026:61226: Moderate: pam security update
Moderate: pam security update
Other sources
Pluggable Authentication Modules (PAM) provide a system to set up authentication policies without the need to recompile programs to handle authentication.Security Fix(es): linux-pam: Plaintext password recovery via timing discrepancy in pamuserdb module (CVE-2026-54411) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/pamto a version that resolves this vulnerability.Fixed in 1.5.1-15.el9_2.3 - Upgrade
Upgrade
redhat/pam-debuginfoto a version that resolves this vulnerability.Fixed in 1.5.1-15.el9_2.3 - Upgrade
Upgrade
redhat/pam-debugsourceto a version that resolves this vulnerability.Fixed in 1.5.1-15.el9_2.3 - Upgrade
Upgrade
redhat/pam-develto a version that resolves this vulnerability.Fixed in 1.5.1-15.el9_2.3 - Upgrade
Upgrade
redhat/pam-docsto a version that resolves this vulnerability.Fixed in 1.5.1-15.el9_2.3 - Upgrade
Upgrade
redhat/pamto a version that resolves this vulnerability.Fixed in 1.5.1-15.el9_2.3.aa - Upgrade
Upgrade
redhat/pam-debuginfoto a version that resolves this vulnerability.Fixed in 1.5.1-15.el9_2.3.aa - Upgrade
Upgrade
redhat/pam-debugsourceto a version that resolves this vulnerability.Fixed in 1.5.1-15.el9_2.3.aa - Upgrade
Upgrade
redhat/pam-develto a version that resolves this vulnerability.Fixed in 1.5.1-15.el9_2.3.aa - Upgrade
Upgrade
redhat/pam-docsto a version that resolves this vulnerability.Fixed in 1.5.1-15.el9_2.3.aa
Event History
Frequently Asked Questions
Which deployments should be prioritized for remediation?
Prioritize systems using the pam_userdb module, as the security fix addresses a timing discrepancy in that module that can enable plaintext password recovery. The advisory applies to the Red Hat PAM packages and associated debuginfo, debugsource, devel, and documentation packages listed in the update.
Which Red Hat platform offerings are listed with this update?
The update lists Red Hat Enterprise Linux for Power, little endian Extended Life Cycle; Red Hat Enterprise Linux Server for Power LE Update Services for SAP Solutions; and Red Hat Enterprise Linux for ARM 64 with 4 years of updates.