[CLSA-2026:1790600614] pam: Fix of 3 CVEs
Type:
security
Severity:
None
Release date:
2026-09-28 13:03:43 UTC
Description:
- Rebase onto the vendor's 1.1.8-23.0.3 sources - CVE-2024-10041: fix possibility of leakage of secret information stored in memory - CVE-2025-6020: take the vendor's fix and carry the parts of ours it omits: upstream 976c2007, namespace.init path-safety flags, helper fd sanitizing - CVE-2024-22365 is now fixed by the vendor's pam_namespace rewrite, which replaces protect_dir() with secure_opendir(); the TuxCare duplicate is dropped
Updated packages:
  • pam-1.1.8-23.0.3.el7.tuxcare.els1.i686.rpm
    sha:641763ab04fa535607ce2a995bdeff068bc7d529a9490d9bf15e8e699a040570
  • pam-1.1.8-23.0.3.el7.tuxcare.els1.x86_64.rpm
    sha:8df04b5e397c9558f2732d5fce5397ec713d5e1e972cd01653f56ccf13c4b853
  • pam-devel-1.1.8-23.0.3.el7.tuxcare.els1.i686.rpm
    sha:3cd5c50f3094696a338dc8a50cdf3ece626724bb9bf6b2ea52b414fcd2e99af3
  • pam-devel-1.1.8-23.0.3.el7.tuxcare.els1.x86_64.rpm
    sha:6d29445905a104e5b5f36364fdcdcccb391a6a57848e4a5d9bbdc2033279a660
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.