Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 493
Alerts This Week
Warning Icon 1 493

Ubuntu 26.04 LTS Advisory 8601-1 PAM High Timing Attack

ubuntu
Calendar Grey July 23, 2026
Scroller Ubuntu
A PAM security issue on Ubuntu exposes sensitive information through timing attacks affecting multiple LTS releases.
A timing discrepancy in PAM's pam_userdb module could expose sensitive information, affecting multiple Ubuntu releases

Summary

PAM could be made to expose sensitive information.

Software Description:

- pam: Pluggable Authentication Modules

Details:

It was discovered that PAM had a timing discrepancy in the pam_userdb

module when comparing plaintext passwords. An attacker could possibly use

this issue to obtain sensitive information by measuring response-timing

differences during repeated authentication attempts.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 26.04 LTS
  libpam-modules                  1.7.0-5ubuntu3.1

Ubuntu 24.04 LTS
  libpam-modules                  1.5.3-5ubuntu5.6

Ubuntu 22.04 LTS
  libpam-modules                  1.4.0-11ubuntu2.7

After a standard system update you need to reboot your computer to make
all the necessary changes.

References

https://ubuntu.com/security/notices/USN-8601-1

CVE-2026-54411

Severity
important
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-8601-1

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.