RHSA-2026:61225: Moderate: pam security update
Moderate: pam security update
Other sources
Pluggable Authentication Modules (PAM) provide a system to set up authentication policies without the need to recompile programs to handle authentication.Security Fix(es): linux-pam: Plaintext password recovery via timing discrepancy in pamuserdb module (CVE-2026-54411) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/pamto a version that resolves this vulnerability.Fixed in 1.3.1-26.el8_8.3 - Upgrade
Upgrade
redhat/pam-debuginfoto a version that resolves this vulnerability.Fixed in 1.3.1-26.el8_8.3 - Upgrade
Upgrade
redhat/pam-debugsourceto a version that resolves this vulnerability.Fixed in 1.3.1-26.el8_8.3 - Upgrade
Upgrade
redhat/pam-develto a version that resolves this vulnerability.Fixed in 1.3.1-26.el8_8.3
Event History
Frequently Asked Questions
Which components should be prioritized for this update?
Prioritize systems using the redhat/pam package, particularly where the pam_userdb module is part of the authentication configuration. Corresponding pam-devel, pam-debuginfo, and pam-debugsource packages are also listed in the advisory.
What is the security impact addressed by this update?
The update addresses CVE-2026-54411, a timing discrepancy in the pam_userdb module that can allow plaintext password recovery. The advisory classifies the update as Moderate severity.
Which Red Hat platforms are listed as affected?
The advisory lists Red Hat Enterprise Linux for x86_64 Update Services for SAP Solutions, Red Hat Enterprise Linux Server TUS, Red Hat Enterprise Linux for x86_64 Extended Life Cycle Long Life, and Red Hat Enterprise Linux Server for Power LE Update Services for SAP Solutions.