[CLSA-2026:1790600758] pam: Fix of 3 CVEs
Type:
security
Severity:
None
Release date:
2026-09-28 13:06:06 UTC
Description:
- Rebase onto the vendor's 1.1.8-23.0.3 sources - CVE-2024-10041: fix possibility of leakage of secret information stored in memory - CVE-2025-6020: take the vendor's fix and carry the parts of ours it omits: upstream 976c2007, namespace.init path-safety flags, helper fd sanitizing - CVE-2024-22365 is now fixed by the vendor's pam_namespace rewrite, which replaces protect_dir() with secure_opendir(); the TuxCare duplicate is dropped
Updated packages:
  • pam-1.1.8-23.0.3.el7.tuxcare.els1.i686.rpm
    sha:ff191df46e570b723ff6d5af02c4984856de848b618274284564f01b593ecfa0
  • pam-1.1.8-23.0.3.el7.tuxcare.els1.x86_64.rpm
    sha:2a297b6c9ba74c88fb50964e37780b140b33f55a2b2e5d4524e2123eae768aa5
  • pam-devel-1.1.8-23.0.3.el7.tuxcare.els1.i686.rpm
    sha:85127041932271036c846f2d230f199494d4762e1539404cfb4c9c0ed12de02b
  • pam-devel-1.1.8-23.0.3.el7.tuxcare.els1.x86_64.rpm
    sha:9242b769f814fc06d2d22c1c7fea158b89b53ab6647cbdb65a34418ba04d225e
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.