Skip to main content
EPSS 0.3%top 75%

Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update

0
Medium
Published: 07/02/2026 (07/02/2026, 18:21:37 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

This update includes the following RPMs: pam: * pam-1.7.2-2.2.hum1 (aarch64, x86_64) * pam-devel-1.7.2-2.2.hum1 (aarch64, x86_64) * pam-doc-1.7.2-2.2.hum1 (noarch) * pam-libs-1.7.2-2.2.hum1 (aarch64, x86_64) * pam-1.7.2-2.2.hum1.src (src) Security Fix(es): pam: * CVE-2026-54411

Affected software

Affected versions
Red HatRed Hat Hardened Imagesaarch64pam-main@aarch64Red Hat Enterprise LinuxRed Hat Enterprise Linux BaseOS (v. 8)srcpam-0:1.3.1-40.el8_10.srcRed Hat Enterprise Linux AppStream (v. 10)Red Hat Enterprise Linux BaseOS (v. 10)Open SourceOpen Source PAMOracleOracle LinuxRESFRed Hat Enterprise Linux BaseOS AUS (v.8.6)Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.6)Red Hat Enterprise Linux BaseOS AUS (v.8.4)Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4)

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/16/2026, 17:57:58 UTC

Technical Analysis

CVE-2026-54411 is a timing discrepancy vulnerability in the pam_userdb module of Linux-PAM, affecting Red Hat Hardened Images. The flaw allows an attacker with local or adjacent network access to recover plaintext passwords by repeatedly attempting authentication and measuring timing differences in password comparison. This vulnerability only applies when pam_userdb is configured to store and compare plaintext credentials, a non-default and discouraged setup in Red Hat Enterprise Linux environments. Red Hat has released updated RPM packages (pam-1.7.2-2.2.hum1 and related) to fix this issue. The vulnerability is categorized under CWE-208 (Observable Timing Discrepancy).

Potential Impact

An attacker with local or network-adjacent access can exploit this vulnerability to recover plaintext passwords by analyzing timing discrepancies during authentication. The impact is limited by the requirement that pam_userdb be configured to store plaintext passwords, which is not the default configuration in Red Hat products. There is no impact on integrity or availability, and exploitation requires repeated authentication attempts.

Mitigation Recommendations

Red Hat has released updated packages that fix this vulnerability. Administrators should apply the security update to upgrade pam and related packages to version 1.7.2-2.2.hum1 or later. Additionally, to mitigate the issue, ensure that the pam_userdb module is not configured to store or compare plaintext credentials. Use strong cryptographic hashing methods in pam_userdb configuration or disable the module if not required. Avoid using 'crypt=none' or omitting the 'crypt=' argument. After configuration changes, restart services relying on PAM to apply the changes.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_vex
Csaf Version
2.0
Publisher
Microsoft Security Response Center
Advisory Id
msrc_CVE-2026-54411
Cve Count
1

Threat ID: 6a3270780b89be68881d7a14

Added to database: 06/17/2026, 10:01:28 UTC

Last enriched: 08/16/2026, 17:57:58 UTC

Last updated: 09/15/2026, 10:01:33 UTC

Views: 126

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses