rpm package
almalinux/pam-libs
pkg:rpm/almalinux/pam-libs
Vulnerabilities (2)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-54411 | Med | 5.9 | < 1.6.1-9.el10_2.1 | 1.6.1-9.el10_2.1 | Jun 14, 2026 | Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling | |
| CVE-2025-6020 | Hig | 7.8 | < 1.6.1-8.el10 | 1.6.1-8.el10 | Jun 17, 2025 | A flaw was found in linux-pam. The module pam_namespace may use access user-controlled paths without proper protection, allowing local users to elevate their privileges to root via multiple symlink attacks and race conditions. |
- affected < 1.6.1-9.el10_2.1fixed 1.6.1-9.el10_2.1
Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling
- affected < 1.6.1-8.el10fixed 1.6.1-8.el10
A flaw was found in linux-pam. The module pam_namespace may use access user-controlled paths without proper protection, allowing local users to elevate their privileges to root via multiple symlink attacks and race conditions.