- What: Security update for PAM modules in Red Hat Enterprise Linux
- Impact: Systems using PAM may be vulnerable to plaintext password recovery
Red Hat Product Errata RHSA-2026:61229 - Security Advisory Issued: 2026-08-31 Updated: 2026-08-31 RHSA-2026:61229 - Security Advisory Overview Updated Packages Synopsis Moderate: pam security update Type/Severity Security Advisory: Moderate Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for pam is now available for Red Hat Enterprise Linux 10.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Pluggable Authentication Modules (PAM) provide a system to set up authentication policies without the need to recompile programs to handle authentication. Security Fix(es): linux-pam: Plaintext password recovery via timing discrepancy in pam_userdb module (CVE-2026-54411) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.0 x86_64 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.0 s390x Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.0 ppc64le Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.0 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.0 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.0 s390x Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.0 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.0 x86_64 Fixes BZ - 2488766 - CVE-2026-54411 linux-pam: Plaintext password recovery via timing discrepancy in pam_userdb module CVEs CVE-2026-54411 References https://access.redhat.com/security/updates/classification/#moderate Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.0 SRPM pam-1.6.1-8.el10_0.1.src.rpm SHA-256: 89d82236de58a3816c1f3e9d20218443613f68d142ee951b3feb1fad004556e4 x86_64 pam-1.6.1-8.el10_0.1.x86_64.rpm SHA-256: acebab2f1f8c667626fefe2604e0aa9e709a498d07c3c1995d526801703604d5 pam-debuginfo-1.6.1-8.el10_0.1.x86_64.rpm SHA-256: 427a0a8e52f6e5801ee93af3edda2cfad4656cb4ef7457525f38114843daf456 pam-debuginfo-1.6.1-8.el10_0.1.x86_64.rpm SHA-256: 427a0a8e52f6e5801ee93af3edda2cfad4656cb4ef7457525f38114843daf456 pam-debugsource-1.6.1-8.el10_0.1.x86_64.rpm SHA-256: 227e6ed855bb2f8bfbb648dabc3cee8ac6357989ba738d5562bfa57a01df77ea pam-debugsource-1.6.1-8.el10_0.1.x86_64.rpm SHA-256: 227e6ed855bb2f8bfbb648dabc3cee8ac6357989ba738d5562bfa57a01df77ea pam-devel-1.6.1-8.el10_0.1.x86_64.rpm SHA-256: 1da2ed53c3f0f1022750f945dab7c543ce570f86e6202aa2b26899100faa5c06 pam-libs-1.6.1-8.el10_0.1.x86_64.rpm SHA-256: 344366327e29bcdb678c295b60d812d406b74da701118404be61380e3b0b2e59 pam-libs-debuginfo-1.6.1-8.el10_0.1.x86_64.rpm SHA-256: b606a63d1723f98407d0c6d0eb69742681dce0cbf0d19f0742ff0c8440aa2d81 pam-libs-debuginfo-1.6.1-8.el10_0.1.x86_64.rpm SHA-256: b606a63d1723f98407d0c6d0eb69742681dce0cbf0d19f0742ff0c8440aa2d81 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.0 SRPM pam-1.6.1-8.el10_0.1.src.rpm SHA-256: 89d82236de58a3816c1f3e9d20218443613f68d142ee951b3feb1fad004556e4 s390x pam-1.6.1-8.el10_0.1.s390x.rpm SHA-256: 935d0f052f3af844fd3558a5d645609e0cf1ad960ac499e0f96bb78ef2fdf34e pam-debuginfo-1.6.1-8.el10_0.1.s390x.rpm SHA-256: 75d9e206256d387ada8e3f465cd85c626ed0fb8cf45a959abbbd4bf72f176cac pam-debuginfo-1.6.1-8.el10_0.1.s390x.rpm SHA-256: 75d9e206256d387ada8e3f465cd85c626ed0fb8cf45a959abbbd4bf72f176cac pam-debugsource-1.6.1-8.el10_0.1.s390x.rpm SHA-256: 45a680d570a7cfb069fdab10e2c974d51cb8ec82ea017a725909df22d5c02485 pam-debugsource-1.6.1-8.el10_0.1.s390x.rpm SHA-256: 45a680d570a7cfb069fdab10e2c974d51cb8ec82ea017a725909df22d5c02485 pam-devel-1.6.1-8.el10_0.1.s390x.rpm SHA-256: cb3dbc232758b6661e939cfc2dfd54b2557da5d5cdf30e4b037424462b675e42 pam-libs-1.6.1-8.el10_0.1.s390x.rpm SHA-256: 971a5fc032686d12f19ed0c9cd74215b59826d0df86971f4f3c8e8c740175d95 pam-libs-debuginfo-1.6.1-8.el10_0.1.s390x.rpm SHA-256: 56949505236ec163f2e596692c4e0563296d9b0efe9723af33c4e9734929511f pam-libs-debuginfo-1.6.1-8.el10_0.1.s390x.rpm SHA-256: 56949505236ec163f2e596692c4e0563296d9b0efe9723af33c4e9734929511f Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.0 SRPM pam-1.6.1-8.el10_0.1.src.rpm SHA-256: 89d82236de58a3816c1f3e9d20218443613f68d142ee951b3feb1fad004556e4 ppc64le pam-1.6.1-8.el10_0.1.ppc64le.rpm SHA-256: c6cc3e006d3cf6eb9f6c852151ae55c0ea48792428dd419dea85afb7d5a4cdc2 pam-debuginfo-1.6.1-8.el10_0.1.ppc64le.rpm SHA-256: 50082c1454c9ce4bf947e477a5a8dd2b773df68281c8b8ef928c715ca34246ed pam-debuginfo-1.6.1-8.el10_0.1.ppc64le.rpm SHA-256: 50082c1454c9ce4bf947e477a5a8dd2b773df68281c8b8ef928c715ca34246ed pam-debugsource-1.6.1-8.el10_0.1.ppc64le.rpm SHA-256: 242342bb8f7f849bfdca83a51e2040b53162adbfe7f507b62658c118b8e508b7 pam-debugsource-1.6.1-8.el10_0.1.ppc64le.rpm SHA-256: 242342bb8f7f849bfdca83a51e2040b53162adbfe7f507b62658c118b8e508b7 pam-devel-1.6.1-8.el10_0.1.ppc64le.rpm SHA-256: 84a5bf9a2e7c47df236567e7200e3548511d5da1b1fd72e5cddb792ea9d0fa42 pam-libs-1.6.1-8.el10_0.1.ppc64le.rpm SHA-256: 574bcc541d379366edf8b8a5713873716a5a50729127d9b622745e45189dc1a2 pam-libs-debuginfo-1.6.1-8.el10_0.1.ppc64le.rpm SHA-256: 32201f389aa36d8a0ac4bf157a64c431f0babcb30a045ea807a0bcdd535a16ff pam-libs-debuginfo-1.6.1-8.el10_0.1.ppc64le.rpm SHA-256: 32201f389aa36d8a0ac4bf157a64c431f0babcb30a045ea807a0bcdd535a16ff Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.0 SRPM pam-1.6.1-8.el10_0.1.src.rpm SHA-256: 89d82236de58a3816c1f3e9d20218443613f68d142ee951b3feb1fad004556e4 aarch64 pam-1.6.1-8.el10_0.1.aarch64.rpm SHA-256: b5d18b8c3ddcf19fd3f5b888cc3d64a1fccb35f897e8d535c67c9c95d79fbfd4 pam-debuginfo-1.6.1-8.el10_0.1.aarch64.rpm SHA-256: a5850997fbd10cee81e988cf34898c11e5890d3d07ad005802a36550e11d105f pam-debuginfo-1.6.1-8.el10_0.1.aarch64.rpm SHA-256: a5850997fbd10cee81e988cf34898c11e5890d3d07ad005802a36550e11d105f pam-debugsource-1.6.1-8.el10_0.1.aarch64.rpm SHA-256: 3bce20392f199ad72c8544940b042fad28dbe21d5e6bf3b388f1bfb9f8a914b4 pam-debugsource-1.6.1-8.el10_0.1.aarch64.rpm SHA-256: 3bce20392f199ad72c8544940b042fad28dbe21d5e6bf3b388f1bfb9f8a914b4 pam-devel-1.6.1-8.el10_0.1.aarch64.rpm SHA-256: 5f2066337f0654ba7ac0a89299a07eb9b0cf92524aa0a4cb3c60b943a527597f pam-libs-1.6.1-8.el10_0.1.aarch64.rpm SHA-256: b58028760c0e4f1055f836f3070bdccb32ba3da74c7027bb975592220c1f1d38 pam-libs-debuginfo-1.6.1-8.el10_0.1.aarch64.rpm SHA-256: 64352b4b87d6f50367c76da762540e147f9c660ef5c7cf28d45d615a728a8085 pam-libs-debuginfo-1.6.1-8.el10_0.1.aarch64.rpm SHA-256: 64352b4b87d6f50367c76da762540e147f9c660ef5c7cf28d45d615a728a8085 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.0 SRPM pam-1.6.1-8.el10_0.1.src.rpm SHA-256: 89d82236de58a3816c1f3e9d20218443613f68d142ee951b3feb1fad004556e4 aarch64 pam-1.6.1-8.el10_0.1.aarch64.rpm SHA-256: b5d18b8c3ddcf19fd3f5b888cc3d64a1fccb35f897e8d535c67c9c95d79fbfd4 pam-debuginfo-1.6.1-8.el10_0.1.aarch64.rpm SHA-256: a5850997fbd10cee81e988cf34898c11e5890d3d07ad005802a36550e11d105f pam-debuginfo-1.6.1-8.el10_0.1.aarch64.rpm SHA-256: a5850997fbd10cee81e988cf34898c11e5890d3d07ad005802a36550e11d105f pam-debugsource-1.6.1-8.el10_0.1.aarch64.rpm SHA-256: 3bce20392f199ad72c8544940b042fad28dbe21d5e6bf3b388f1bfb9f8a914b4 pam-debugsource-1.6.1-8.el10_0.1.aarch64.rpm SHA-256: 3bce20392f199ad72c8544940b042fad28dbe21d5e6bf3b388f1bfb9f8a914b4 pam-devel-1.6.1-8.el10_0.1.aarch64.rpm SHA-256: 5f2066337f0654ba7ac0a89299a07eb9b0cf92524aa0a4cb3c60b943a527597f pam-libs-1.6.1-8.el10_0.1.aarch64.rpm SHA-256: b58028760c0e4f1055f836f3070bdccb32ba3da74c7027bb975592220c1f1d38 pam-libs-debuginfo-1.6.1-8.el10_0.1.aarch64.rpm SHA-256: 64352b4b87d6f50367c76da762540e147f9c660ef5c7cf28d45d615a728a8085 pam-libs-debuginfo-1.6.1-8.el10_0.1.aarch64.rpm SHA-256: 64352b4b87d6f50367c76da762540e147f9c660ef5c7cf28d45d615a728a8085 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.0 SRPM pam-1.6.1-8.el10_0.1.src.rpm SHA-256: 89d82236de58a3816c1f3e9d20218443613f68d142ee951b3feb1fad004556e4 s390x pam-1.6.1-8.el10_0.1.s390x.rpm SHA-256: 935d0f052f3af844fd3558a5d645609e0cf1ad960ac499e0f96bb78ef2fdf34e pam-debuginfo-1.6.1-8.el10_0.1.s390x.rpm SHA-256: 75d9e206256d387ada8e3f465cd85c626ed0fb8cf45a959abbbd4bf72f176cac pam-debuginfo-1.6.1-8.el10_0.1.s390x.rpm SHA-256: 75d9e206256d387ada8e3f465cd85c626ed0fb8cf45a959abbbd4bf72f176cac pam-debugsource-1.6.1-8.el10_0.1.s390x.rpm SHA-256: 45a680d570a7cfb069fdab10e2c974d51cb8ec82ea017a725909df22d5c02485 pam-debugsource-1.6.1-8.el10_0.1.s390x.rpm SHA-256: 45a680d570a7cfb069fdab10e2c974d51cb8ec82ea017a725909df22d5c02485 pam-devel-1.6.1-8.el10_0.1.s390x.rpm SHA-256: cb3dbc232758b6661e939cfc2dfd54b2557da5d5cdf30e4b037424462b675e42 pam-libs-1.6.1-8.el10_0.1.s390x.rpm SHA-256: 971a5fc032686d12f19ed0c9cd74215b59826d0df86971f4f3c8e8c740175d95 pam-libs-debuginfo-1.6.1-8.el10_0.1.s390x.rpm SHA-256: 56949505236ec163f2e596692c4e0563296d9b0efe9723af33c4e9734929511f pam-libs-debuginfo-1.6.1-8.el10_0.1.s390x.rpm SHA-256: 56949505236ec163f2e596692c4e0563296d9b0efe9723af33c4e9734929511f Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.0 SRPM pam-1.6.1-8.el10_0.1.src.rpm SHA-256: 89d82236de58a3816c1f3e9d20218443613f68d142ee951b3feb1fad004556e4 ppc64le pam-1.6.1-8.el10_0.1.ppc64le.rpm SHA-256: c6cc3e006d3cf6eb9f6c852151ae55c0ea48792428dd419dea85afb7d5a4cdc2 pam-debuginfo-1.6.1-8.el10_0.1.ppc64le.