pam-1.5.1-25.el9_6

エラータID: AXSA:2025-10566:04

Release date: 
Wednesday, July 23, 2025 - 18:27
Subject: 
pam-1.5.1-25.el9_6
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
High
Description: 

Pluggable Authentication Modules (PAM) provide a system to set up authentication policies without the need to recompile programs to handle authentication.

Security Fix(es):

* linux-pam: Linux-pam directory Traversal (CVE-2025-6020)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2025-6020
A flaw was found in linux-pam. The module pam_namespace may use access user-controlled paths without proper protection, allowing local users to elevate their privileges to root via multiple symlink attacks and race conditions.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. pam-1.5.1-25.el9_6.src.rpm
    MD5: 39f9d5eea087f696124f71c78dd8cf8c
    SHA-256: c5b130154cc56d152442aada80126aa4c7e667ee7ea49ee50b30cc1f05f4b9e5
    Size: 1.07 MB

Asianux Server 9 for x86_64
  1. pam-1.5.1-25.el9_6.i686.rpm
    MD5: ba9a71345b00ffc141d4d1f1bf8ffa50
    SHA-256: 8453688d89154e32a851a2be95507053675c4a1ccb5813cbd180b8d08dc40651
    Size: 625.90 kB
  2. pam-1.5.1-25.el9_6.x86_64.rpm
    MD5: 3c54446a8c9fcdda00168a8d7c5113e4
    SHA-256: 9a68adc9220f64870372427559c0c4c74194d1f39973959fdab4d02b2ddf6293
    Size: 602.41 kB
  3. pam-devel-1.5.1-25.el9_6.i686.rpm
    MD5: accaa276c8c874e21f633e0009229f43
    SHA-256: 14bc79f339bd48d8966eff284131c1f592afe40ef5030500a97147552c283297
    Size: 163.63 kB
  4. pam-devel-1.5.1-25.el9_6.x86_64.rpm
    MD5: 26aeb3e4074b3e0e1d198180d1ac2ee5
    SHA-256: 05950d0a4b94ded801c3282303bd588f5d62f888508ea463ed864031c970f4ec
    Size: 163.65 kB
  5. pam-docs-1.5.1-25.el9_6.x86_64.rpm
    MD5: 9d5c5df1973754567d7efe450db96d47
    SHA-256: 9fb753341b3e0b95e88a4b60c86983d7b03988afef05a103e5621ccf11dc6b9a
    Size: 128.83 kB