RHSA-2026:61228: Moderate: pam security update
Moderate: pam security update
Other sources
Pluggable Authentication Modules (PAM) provide a system to set up authentication policies without the need to recompile programs to handle authentication.Security Fix(es): linux-pam: Plaintext password recovery via timing discrepancy in pamuserdb module (CVE-2026-54411) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/pamto a version that resolves this vulnerability.Fixed in 1.5.1-24.el9_4.2 - Upgrade
Upgrade
redhat/pam-debuginfoto a version that resolves this vulnerability.Fixed in 1.5.1-24.el9_4.2 - Upgrade
Upgrade
redhat/pam-debugsourceto a version that resolves this vulnerability.Fixed in 1.5.1-24.el9_4.2 - Upgrade
Upgrade
redhat/pam-develto a version that resolves this vulnerability.Fixed in 1.5.1-24.el9_4.2 - Upgrade
Upgrade
redhat/pam-docsto a version that resolves this vulnerability.Fixed in 1.5.1-24.el9_4.2 - Upgrade
Upgrade
redhat/pamto a version that resolves this vulnerability.Fixed in 1.5.1-24.el9_4.2.aa - Upgrade
Upgrade
redhat/pam-debuginfoto a version that resolves this vulnerability.Fixed in 1.5.1-24.el9_4.2.aa - Upgrade
Upgrade
redhat/pam-debugsourceto a version that resolves this vulnerability.Fixed in 1.5.1-24.el9_4.2.aa - Upgrade
Upgrade
redhat/pam-develto a version that resolves this vulnerability.Fixed in 1.5.1-24.el9_4.2.aa - Upgrade
Upgrade
redhat/pam-docsto a version that resolves this vulnerability.Fixed in 1.5.1-24.el9_4.2.aa
Event History
Frequently Asked Questions
Is every PAM authentication configuration affected?
The identified issue is specifically in the pam_userdb module. The advisory does not state that other PAM modules or all PAM authentication paths are affected.
What should administrators check to determine whether this is relevant to their systems?
Check whether pam_userdb is deployed or configured in authentication policies, and whether the system uses the PAM packages covered by this update. The advisory names pam, pam-debuginfo, pam-debugsource, pam-devel, and pam-docs.
Which Red Hat platform variants are explicitly listed?
The advisory lists Red Hat Enterprise Linux Server - AUS, Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle, and Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle.