Release date:
2026-09-30 16:33:34 UTC
Description:
- Rebase onto the vendor's 1.1.8-23.0.3 sources
- CVE-2024-10041: fix possibility of leakage of secret information
stored in memory
- CVE-2025-6020: take the vendor's fix and carry the parts of ours it
omits: upstream 976c2007, namespace.init path-safety flags, helper fd
sanitizing
- CVE-2024-22365 is now fixed by the vendor's pam_namespace rewrite, which
replaces protect_dir() with secure_opendir(); the TuxCare duplicate is dropped
Updated packages:
-
pam-1.1.8-23.0.3.el7.tuxcare.els1.aarch64.rpm
sha:47f69ba0055507e4f43cd9686a96962ec2fb352ba5b682b7c647ff2ea8ba571f
-
pam-1.1.8-23.0.3.el7.tuxcare.els1.i686.rpm
sha:e9e07471aa0557c9b2ec02ec7dd4d42a9926bcbed6c83371de83be66ba718c4c
-
pam-1.1.8-23.0.3.el7.tuxcare.els1.x86_64.rpm
sha:d80d989402567d84d4740b4b784d4c1dd36a916bccb8a6210753906bab5d3030
-
pam-devel-1.1.8-23.0.3.el7.tuxcare.els1.aarch64.rpm
sha:3d7b84ef37ab134c67aff700edb87b320b266ed00edb3851d02c5e54ee9855be
-
pam-devel-1.1.8-23.0.3.el7.tuxcare.els1.i686.rpm
sha:ad543f15f15f02adb417487e69c66f7ff840e2e976fb31c27f8b918ff8673075
-
pam-devel-1.1.8-23.0.3.el7.tuxcare.els1.x86_64.rpm
sha:43c2a93fd4d0ea0519bc8bc4df937fb5526683811b6a492ebc7953cb16646ed2
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.