Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 454
Alerts This Week
Warning Icon 1 454

Fedora 43 pam Important Timing Attack Fix 2026-adc8ddbeaa

fedora
Calendar Grey July 25, 2026
Scroller Fedora
Fix for timing leak in pam_userdb module improves authentication security in Fedora 43.
Fedora released a security update for the PAM library to fix a timing leak issue in the pam_userdb module, addressing CVE-2026-54411 and enhancing authentication security.

Summary

PAM (Pluggable Authentication Modules) is a system security tool that

allows system administrators to set authentication policy without

having to recompile programs that handle authentication.

Update Information:

pam_userdb: fix password comparison timing leak

Change Log

* Fri Jul 10 2026 Iker Pedrosa - 1.7.1-5 - pam_userdb: fix password comparison timing leak Resolves: #2496416 Resolves: CVE-2026-54411

References


[ 1 ] Bug #2496416 - CVE-2026-54411 pam: Plaintext password recovery via timing discrepancy in pam_userdb module [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2496416

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-adc8ddbeaa' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
important
Lowest
Low
Medium
High
Critical

Name: pam
Product: Fedora 43
Version: 1.7.1
Release: 5.fc43
Summary: An extensible library which provides authentication for applications

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.