[CLSA-2025:1749570465] pam: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2025-06-10 15:47:50 UTC
Description:
- CVE-2024-10041: fix possibility of leakage of secret information stored in memory - CVE-2024-22365: fix potential DoS via mkfifo because the openat call lacks O_DIRECTORY
Updated packages:
  • pam-1.1.8-23.0.1.el7.tuxcare.els1.i686.rpm
    sha:5970602e0f3c2b8126c931d68d7cb5b5e86fca837e5491bf478b7380031c0091
  • pam-1.1.8-23.0.1.el7.tuxcare.els1.x86_64.rpm
    sha:b921d0fbbc4afd12b6fb65f37dcc6874916f28eb9927e6b2dca6861aa111e9e2
  • pam-devel-1.1.8-23.0.1.el7.tuxcare.els1.i686.rpm
    sha:01a5280225c448920dced1c578683a56dd9658ce4d3faa187d13ddda680b2970
  • pam-devel-1.1.8-23.0.1.el7.tuxcare.els1.x86_64.rpm
    sha:16934c93d1eab9eabe1640e40c84f1af144451928588603f6a6ddebbc1d17b7c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.