Security News

Cybersecurity news aggregator

🐧
MEDIUM Vulnerabilities Ubuntu Security

USN-8601-1: PAM vulnerability

  • What: PAM vulnerability in Ubuntu allows timing-based information leakage
  • Impact: Systems using PAM could be exploited to expose sensitive information
Read Full Article →

Ubuntu Security Notices USN-8601-1 USN-8601-1: PAM vulnerability Publication date 23 July 2026 Overview PAM could be made to expose sensitive information. Releases 26.04 LTS 24.04 LTS 22.04 LTS Open side navigation Close side navigation Packages Details Update instructions References Packages pam - Pluggable Authentication Modules Details It was discovered that PAM had a timing discrepancy in the pam_userdb module when comparing plaintext passwords. An attacker could possibly use this issue to obtain sensitive information by measuring response-timing differences during repeated authentication attempts. It was discovered that PAM had a timing discrepancy in the pam_userdb module when comparing plaintext passwords. An attacker could possibly use this issue to obtain sensitive information by measuring response-timing differences during repeated authentication attempts. Update instructions After a standard system update you need to reboot your computer to make all the necessary changes. Learn more about how to get the fixes. The problem can be corrected by updating your system to the following package versions: Ubuntu Release Package Version 26.04 LTS resolute libpam-modules – 1.7.0-5ubuntu3.1 24.04 LTS noble libpam-modules – 1.5.3-5ubuntu5.6 22.04 LTS jammy libpam-modules – 1.4.0-11ubuntu2.7 Reduce your security exposure Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines. Get Ubuntu Pro References CVE-2026-54411 CVE-2026-54411

Share this article