pam-1.3.1-40.el8_10

エラータID: AXSA:2026-1577:02

リリース日: 
2026/08/19 Wednesday - 19:07
題名: 
pam-1.3.1-40.el8_10
影響のあるチャネル: 
Asianux Server 8 for x86_64
Severity: 
Moderate
Description: 

Pluggable Authentication Modules (PAM) provide a system to set up authentication policies without the need to recompile programs to handle authentication.

Security Fix(es):

* linux-pam: Plaintext password recovery via timing discrepancy in pam_userdb module (CVE-2026-54411)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-54411
Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences.

解決策: 

Update packages.

追加情報: 

N/A

ダウンロード: 

SRPMS
  1. pam-1.3.1-40.el8_10.src.rpm
    MD5: baaa0929f21940bff211f0d49720adfa
    SHA-256: 720a2e39d79d16898ab7bd62eedb08350683e4102aaa046e924809923708b828
    Size: 1.13 MB

Asianux Server 8 for x86_64
  1. pam-1.3.1-40.el8_10.i686.rpm
    MD5: 7582b654d5dfe37927b38a76d147b1b0
    SHA-256: 97ce9dcada9c1d7c3e8ed021cc5407d32ca0d706221408b8638da0fcd5e315d8
    Size: 770.17 kB
  2. pam-1.3.1-40.el8_10.x86_64.rpm
    MD5: 3fc6f50609f1e3dca17fccb1bdcb62df
    SHA-256: 1a8ffd7ebb378df942ad40ed156bc4e8ab9fddeb53f7a14dbe15bf3956d04e6e
    Size: 749.12 kB
  3. pam-devel-1.3.1-40.el8_10.i686.rpm
    MD5: 58e1d51acc32a6703f189398116fc1c8
    SHA-256: bd095fd6e368915e3ab2ad300bc738cdd81a1b805022e769c925e526b561a52d
    Size: 211.62 kB
  4. pam-devel-1.3.1-40.el8_10.x86_64.rpm
    MD5: 6ba6f1a888803ee4684f9fde7b09277f
    SHA-256: 6a79ac8fc4884b79ddcfb5f87bf1d6023c853e73fc6d428c138811a792ac4b14
    Size: 211.63 kB