Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
PAM (Pluggable Authentication Modules) is a system security tool that
allows system administrators to set authentication policy without
having to recompile programs that handle authentication.
Update Information:
pam_userdb: fix password comparison timing leak
* Fri Jul 10 2026 Iker Pedrosa
[ 1 ] Bug #2496416 - CVE-2026-54411 pam: Plaintext password recovery via timing discrepancy in pam_userdb module [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2496416
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-adc8ddbeaa' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
Get the latest Linux and open source security news straight to your inbox.