[CLSA-2026:1790600348] pam: Fix of 3 CVEs
Type:
security
Severity:
None
Release date:
2026-09-29 18:03:32 UTC
Description:
- Rebase onto the vendor's 1.1.8-23.0.3 sources - CVE-2024-10041: fix possibility of leakage of secret information stored in memory - CVE-2025-6020: take the vendor's fix and carry the parts of ours it omits: upstream 976c2007, namespace.init path-safety flags, helper fd sanitizing - CVE-2024-22365 is now fixed by the vendor's pam_namespace rewrite, which replaces protect_dir() with secure_opendir(); the TuxCare duplicate is dropped
Updated packages:
  • pam-1.1.8-23.0.3.el7.tuxcare.els1.i686.rpm
    sha:db553b4368fd03de01d418d9ac812f990660a63c03fa3ceee3224e7c2dac8c38
  • pam-1.1.8-23.0.3.el7.tuxcare.els1.x86_64.rpm
    sha:b36b6baa74693457e356807817f623594a9f113820a413fa9fb47ba1d30b7b94
  • pam-devel-1.1.8-23.0.3.el7.tuxcare.els1.i686.rpm
    sha:e68eb626fe66bbd21e247df739c78c11853fb1055865f0f9a9109c77aeecb217
  • pam-devel-1.1.8-23.0.3.el7.tuxcare.els1.x86_64.rpm
    sha:e49f1d7527a0ec5c5c4e807f39b3a19bc15ab81f8cf167996b5ccf785db45da7
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.