Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update
This update includes the following RPMs: pam: * pam-1.7.2-2.2.hum1 (aarch64, x86_64) * pam-devel-1.7.2-2.2.hum1 (aarch64, x86_64) * pam-doc-1.7.2-2.2.hum1 (noarch) * pam-libs-1.7.2-2.2.hum1 (aarch64, x86_64) * pam-1.7.2-2.2.hum1.src (src) Security Fix(es): pam: * CVE-2026-54411
AI Analysis
Technical Summary
CVE-2026-54411 is a timing discrepancy vulnerability in the pam_userdb module of Linux-PAM, affecting Red Hat Hardened Images. The flaw allows an attacker with local or adjacent network access to recover plaintext passwords by repeatedly attempting authentication and measuring timing differences in password comparison. This vulnerability only applies when pam_userdb is configured to store and compare plaintext credentials, a non-default and discouraged setup in Red Hat Enterprise Linux environments. Red Hat has released updated RPM packages (pam-1.7.2-2.2.hum1 and related) to fix this issue. The vulnerability is categorized under CWE-208 (Observable Timing Discrepancy).
Potential Impact
An attacker with local or network-adjacent access can exploit this vulnerability to recover plaintext passwords by analyzing timing discrepancies during authentication. The impact is limited by the requirement that pam_userdb be configured to store plaintext passwords, which is not the default configuration in Red Hat products. There is no impact on integrity or availability, and exploitation requires repeated authentication attempts.
Mitigation Recommendations
Red Hat has released updated packages that fix this vulnerability. Administrators should apply the security update to upgrade pam and related packages to version 1.7.2-2.2.hum1 or later. Additionally, to mitigate the issue, ensure that the pam_userdb module is not configured to store or compare plaintext credentials. Use strong cryptographic hashing methods in pam_userdb configuration or disable the module if not required. Avoid using 'crypt=none' or omitting the 'crypt=' argument. After configuration changes, restart services relying on PAM to apply the changes.
Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update
Description
This update includes the following RPMs: pam: * pam-1.7.2-2.2.hum1 (aarch64, x86_64) * pam-devel-1.7.2-2.2.hum1 (aarch64, x86_64) * pam-doc-1.7.2-2.2.hum1 (noarch) * pam-libs-1.7.2-2.2.hum1 (aarch64, x86_64) * pam-1.7.2-2.2.hum1.src (src) Security Fix(es): pam: * CVE-2026-54411
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-54411 is a timing discrepancy vulnerability in the pam_userdb module of Linux-PAM, affecting Red Hat Hardened Images. The flaw allows an attacker with local or adjacent network access to recover plaintext passwords by repeatedly attempting authentication and measuring timing differences in password comparison. This vulnerability only applies when pam_userdb is configured to store and compare plaintext credentials, a non-default and discouraged setup in Red Hat Enterprise Linux environments. Red Hat has released updated RPM packages (pam-1.7.2-2.2.hum1 and related) to fix this issue. The vulnerability is categorized under CWE-208 (Observable Timing Discrepancy).
Potential Impact
An attacker with local or network-adjacent access can exploit this vulnerability to recover plaintext passwords by analyzing timing discrepancies during authentication. The impact is limited by the requirement that pam_userdb be configured to store plaintext passwords, which is not the default configuration in Red Hat products. There is no impact on integrity or availability, and exploitation requires repeated authentication attempts.
Mitigation Recommendations
Red Hat has released updated packages that fix this vulnerability. Administrators should apply the security update to upgrade pam and related packages to version 1.7.2-2.2.hum1 or later. Additionally, to mitigate the issue, ensure that the pam_userdb module is not configured to store or compare plaintext credentials. Use strong cryptographic hashing methods in pam_userdb configuration or disable the module if not required. Avoid using 'crypt=none' or omitting the 'crypt=' argument. After configuration changes, restart services relying on PAM to apply the changes.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_vex
- Csaf Version
- 2.0
- Publisher
- Microsoft Security Response Center
- Advisory Id
- msrc_CVE-2026-54411
- Cve Count
- 1
Threat ID: 6a3270780b89be68881d7a14
Added to database: 06/17/2026, 10:01:28 UTC
Last enriched: 08/16/2026, 17:57:58 UTC
Last updated: 09/15/2026, 10:01:33 UTC
Views: 126
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.