Security News

Cybersecurity news aggregator

🔄
MEDIUM Updates Red Hat Errata

RHSA-2026:61225: Moderate: pam security update

  • What: Security update for PAM in Red Hat Enterprise Linux
  • Impact: Systems using PAM may be vulnerable to plaintext password recovery
Read Full Article →

Red Hat Product Errata RHSA-2026:61225 - Security Advisory Issued: 2026-08-31 Updated: 2026-08-31 RHSA-2026:61225 - Security Advisory Overview Updated Packages Synopsis Moderate: pam security update Type/Severity Security Advisory: Moderate Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for pam is now available for Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions and Red Hat Enterprise Linux 8.8 Telecommunications Update Service. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Pluggable Authentication Modules (PAM) provide a system to set up authentication policies without the need to recompile programs to handle authentication. Security Fix(es): linux-pam: Plaintext password recovery via timing discrepancy in pam_userdb module (CVE-2026-54411) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life 8.8 x86_64 Red Hat Enterprise Linux Server - TUS 8.8 x86_64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.8 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.8 x86_64 Fixes BZ - 2488766 - CVE-2026-54411 linux-pam: Plaintext password recovery via timing discrepancy in pam_userdb module CVEs CVE-2026-54411 References https://access.redhat.com/security/updates/classification/#moderate Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life 8.8 SRPM pam-1.3.1-26.el8_8.3.src.rpm SHA-256: d876f9ce2ca05afba269ea2391f9895546a393e77e693cdc5a7c93b79deef7f6 x86_64 pam-1.3.1-26.el8_8.3.i686.rpm SHA-256: 611513682b77099c6d5300a06968bcdeebcfe1389a415edeeb446a264f47f720 pam-1.3.1-26.el8_8.3.x86_64.rpm SHA-256: e65700a2d9920ef0a438f5879902365afb27eeaec42b98b9eb341a69a7c7098f pam-debuginfo-1.3.1-26.el8_8.3.i686.rpm SHA-256: 932293978c52882eb8201d3342708aa387824f4073eda7738409cbbf0a47efad pam-debuginfo-1.3.1-26.el8_8.3.x86_64.rpm SHA-256: 8a5b13926ebeb9defb333e5c8f62a4e0d73fc85d7e46c19b2f5af22fa2601183 pam-debugsource-1.3.1-26.el8_8.3.i686.rpm SHA-256: 3cfb5160889c007f502286ec109084073dd0eac26b2845344cb07ebabe99a02f pam-debugsource-1.3.1-26.el8_8.3.x86_64.rpm SHA-256: 73b2bd8bcd4c90b1d9f4ed39f42d537ae48429f4d9177bfdb92f2765e54d2b80 pam-devel-1.3.1-26.el8_8.3.i686.rpm SHA-256: d19beb6ebda08990a9d866af58ea8171ddbedda523146aa44bdace9d61e4adb6 pam-devel-1.3.1-26.el8_8.3.x86_64.rpm SHA-256: 7bef2013e72da8a4340b5b1223f53bafb736f45f2d608936adf68ee238e0695a Red Hat Enterprise Linux Server - TUS 8.8 SRPM pam-1.3.1-26.el8_8.3.src.rpm SHA-256: d876f9ce2ca05afba269ea2391f9895546a393e77e693cdc5a7c93b79deef7f6 x86_64 pam-1.3.1-26.el8_8.3.i686.rpm SHA-256: 611513682b77099c6d5300a06968bcdeebcfe1389a415edeeb446a264f47f720 pam-1.3.1-26.el8_8.3.x86_64.rpm SHA-256: e65700a2d9920ef0a438f5879902365afb27eeaec42b98b9eb341a69a7c7098f pam-debuginfo-1.3.1-26.el8_8.3.i686.rpm SHA-256: 932293978c52882eb8201d3342708aa387824f4073eda7738409cbbf0a47efad pam-debuginfo-1.3.1-26.el8_8.3.x86_64.rpm SHA-256: 8a5b13926ebeb9defb333e5c8f62a4e0d73fc85d7e46c19b2f5af22fa2601183 pam-debugsource-1.3.1-26.el8_8.3.i686.rpm SHA-256: 3cfb5160889c007f502286ec109084073dd0eac26b2845344cb07ebabe99a02f pam-debugsource-1.3.1-26.el8_8.3.x86_64.rpm SHA-256: 73b2bd8bcd4c90b1d9f4ed39f42d537ae48429f4d9177bfdb92f2765e54d2b80 pam-devel-1.3.1-26.el8_8.3.i686.rpm SHA-256: d19beb6ebda08990a9d866af58ea8171ddbedda523146aa44bdace9d61e4adb6 pam-devel-1.3.1-26.el8_8.3.x86_64.rpm SHA-256: 7bef2013e72da8a4340b5b1223f53bafb736f45f2d608936adf68ee238e0695a Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.8 SRPM pam-1.3.1-26.el8_8.3.src.rpm SHA-256: d876f9ce2ca05afba269ea2391f9895546a393e77e693cdc5a7c93b79deef7f6 ppc64le pam-1.3.1-26.el8_8.3.ppc64le.rpm SHA-256: 9f86b3b4d48461108905decbf8e394e05b44baa1300684616d8d3574270113db pam-debuginfo-1.3.1-26.el8_8.3.ppc64le.rpm SHA-256: 56ca5b70d538de996b73316d0b4dfb47552dcfe43f838cd3691f6d6ad86a179c pam-debugsource-1.3.1-26.el8_8.3.ppc64le.rpm SHA-256: 45fda7c261d1ca49d91510be51db3f8e6eac89f1a5268fa9bc7f50a503788bb4 pam-devel-1.3.1-26.el8_8.3.ppc64le.rpm SHA-256: 417c36b3ba542a93d3ea14347425f067a0543e1dd197de1edd34f433662160e0 Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.8 SRPM pam-1.3.1-26.el8_8.3.src.rpm SHA-256: d876f9ce2ca05afba269ea2391f9895546a393e77e693cdc5a7c93b79deef7f6 x86_64 pam-1.3.1-26.el8_8.3.i686.rpm SHA-256: 611513682b77099c6d5300a06968bcdeebcfe1389a415edeeb446a264f47f720 pam-1.3.1-26.el8_8.3.x86_64.rpm SHA-256: e65700a2d9920ef0a438f5879902365afb27eeaec42b98b9eb341a69a7c7098f pam-debuginfo-1.3.1-26.el8_8.3.i686.rpm SHA-256: 932293978c52882eb8201d3342708aa387824f4073eda7738409cbbf0a47efad pam-debuginfo-1.3.1-26.el8_8.3.x86_64.rpm SHA-256: 8a5b13926ebeb9defb333e5c8f62a4e0d73fc85d7e46c19b2f5af22fa2601183 pam-debugsource-1.3.1-26.el8_8.3.i686.rpm SHA-256: 3cfb5160889c007f502286ec109084073dd0eac26b2845344cb07ebabe99a02f pam-debugsource-1.3.1-26.el8_8.3.x86_64.rpm SHA-256: 73b2bd8bcd4c90b1d9f4ed39f42d537ae48429f4d9177bfdb92f2765e54d2b80 pam-devel-1.3.1-26.el8_8.3.i686.rpm SHA-256: d19beb6ebda08990a9d866af58ea8171ddbedda523146aa44bdace9d61e4adb6 pam-devel-1.3.1-26.el8_8.3.x86_64.rpm SHA-256: 7bef2013e72da8a4340b5b1223f53bafb736f45f2d608936adf68ee238e0695a The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .

Share this article