VYPR

rpm package

almalinux/pam-libs

pkg:rpm/almalinux/pam-libs

Vulnerabilities (2)

  • CVE-2026-54411MedJun 14, 2026
    affected < 1.6.1-9.el10_2.1fixed 1.6.1-9.el10_2.1

    Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling

  • CVE-2025-6020HigJun 17, 2025
    affected < 1.6.1-8.el10fixed 1.6.1-8.el10

    A flaw was found in linux-pam. The module pam_namespace may use access user-controlled paths without proper protection, allowing local users to elevate their privileges to root via multiple symlink attacks and race conditions.