Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2024:10232 - Security Advisory
Issued:
2024-11-25
Updated:
2024-11-25

RHSA-2024:10232 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: pam security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for pam is now available for Red Hat Enterprise Linux 9.4 Extended Update Support.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Pluggable Authentication Modules (PAM) provide a system to set up authentication policies without the need to recompile programs to handle authentication.

Security Fix(es):

  • pam: Improper Hostname Interpretation in pam_access Leads to Access Control Bypass (CVE-2024-10963)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.4 x86_64
  • Red Hat Enterprise Linux Server - AUS 9.4 x86_64
  • Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.4 s390x
  • Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.4 ppc64le
  • Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.4 aarch64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.4 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4 x86_64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.4 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.4 s390x

Fixes

  • BZ - 2324291 - CVE-2024-10963 pam: Improper Hostname Interpretation in pam_access Leads to Access Control Bypass

CVEs

  • CVE-2024-10963

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.4

SRPM
pam-1.5.1-23.el9_4.src.rpm SHA-256: f791b5c9aaf750b8108b8d417889c0ef2ab4c264693724d7153367b542348399
x86_64
pam-1.5.1-23.el9_4.i686.rpm SHA-256: ffc8a49ef51eecbb1f19c28b43c62f6c65c63abb000af88d579f9401143a7ab5
pam-1.5.1-23.el9_4.x86_64.rpm SHA-256: b2a90a84512ccf6acd4a16d48c65b689fd5e44bd545231dffdb8525d783beb94
pam-debuginfo-1.5.1-23.el9_4.i686.rpm SHA-256: 32908ab97d201482c8e0b1cf337bba2676b7a0fd30f6ab58b48e9edc4549dca6
pam-debuginfo-1.5.1-23.el9_4.i686.rpm SHA-256: 32908ab97d201482c8e0b1cf337bba2676b7a0fd30f6ab58b48e9edc4549dca6
pam-debuginfo-1.5.1-23.el9_4.x86_64.rpm SHA-256: e516a1b2b979929adf8299d27019041ea8badbdc434816493fcf608bc2f47412
pam-debuginfo-1.5.1-23.el9_4.x86_64.rpm SHA-256: e516a1b2b979929adf8299d27019041ea8badbdc434816493fcf608bc2f47412
pam-debugsource-1.5.1-23.el9_4.i686.rpm SHA-256: 1b768154fd91212ab80f5724fde0bb4921d202b1a086aa99b18959ca4960e716
pam-debugsource-1.5.1-23.el9_4.i686.rpm SHA-256: 1b768154fd91212ab80f5724fde0bb4921d202b1a086aa99b18959ca4960e716
pam-debugsource-1.5.1-23.el9_4.x86_64.rpm SHA-256: 7003e47ebe8b441219ac2d04e61335e7e8dca01ef50a11868d794c25deafb123
pam-debugsource-1.5.1-23.el9_4.x86_64.rpm SHA-256: 7003e47ebe8b441219ac2d04e61335e7e8dca01ef50a11868d794c25deafb123
pam-devel-1.5.1-23.el9_4.i686.rpm SHA-256: 6ab491de47fcb63f6d50685a13587f67f5f7ca4b7095ae80a52f54289bd7c0cf
pam-devel-1.5.1-23.el9_4.x86_64.rpm SHA-256: 68f5fd880341c068f1c391c9963f5e891f63a0a7f187487e7e4dc4186b77e038
pam-docs-1.5.1-23.el9_4.x86_64.rpm SHA-256: 71a2c584733414a6acae2aee9fb55caf4ac727304c42c8a32e27618fa8b78bea

Red Hat Enterprise Linux Server - AUS 9.4

SRPM
pam-1.5.1-23.el9_4.src.rpm SHA-256: f791b5c9aaf750b8108b8d417889c0ef2ab4c264693724d7153367b542348399
x86_64
pam-1.5.1-23.el9_4.i686.rpm SHA-256: ffc8a49ef51eecbb1f19c28b43c62f6c65c63abb000af88d579f9401143a7ab5
pam-1.5.1-23.el9_4.x86_64.rpm SHA-256: b2a90a84512ccf6acd4a16d48c65b689fd5e44bd545231dffdb8525d783beb94
pam-debuginfo-1.5.1-23.el9_4.i686.rpm SHA-256: 32908ab97d201482c8e0b1cf337bba2676b7a0fd30f6ab58b48e9edc4549dca6
pam-debuginfo-1.5.1-23.el9_4.i686.rpm SHA-256: 32908ab97d201482c8e0b1cf337bba2676b7a0fd30f6ab58b48e9edc4549dca6
pam-debuginfo-1.5.1-23.el9_4.x86_64.rpm SHA-256: e516a1b2b979929adf8299d27019041ea8badbdc434816493fcf608bc2f47412
pam-debuginfo-1.5.1-23.el9_4.x86_64.rpm SHA-256: e516a1b2b979929adf8299d27019041ea8badbdc434816493fcf608bc2f47412
pam-debugsource-1.5.1-23.el9_4.i686.rpm SHA-256: 1b768154fd91212ab80f5724fde0bb4921d202b1a086aa99b18959ca4960e716
pam-debugsource-1.5.1-23.el9_4.i686.rpm SHA-256: 1b768154fd91212ab80f5724fde0bb4921d202b1a086aa99b18959ca4960e716
pam-debugsource-1.5.1-23.el9_4.x86_64.rpm SHA-256: 7003e47ebe8b441219ac2d04e61335e7e8dca01ef50a11868d794c25deafb123
pam-debugsource-1.5.1-23.el9_4.x86_64.rpm SHA-256: 7003e47ebe8b441219ac2d04e61335e7e8dca01ef50a11868d794c25deafb123
pam-devel-1.5.1-23.el9_4.i686.rpm SHA-256: 6ab491de47fcb63f6d50685a13587f67f5f7ca4b7095ae80a52f54289bd7c0cf
pam-devel-1.5.1-23.el9_4.x86_64.rpm SHA-256: 68f5fd880341c068f1c391c9963f5e891f63a0a7f187487e7e4dc4186b77e038
pam-docs-1.5.1-23.el9_4.x86_64.rpm SHA-256: 71a2c584733414a6acae2aee9fb55caf4ac727304c42c8a32e27618fa8b78bea

Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.4

SRPM
pam-1.5.1-23.el9_4.src.rpm SHA-256: f791b5c9aaf750b8108b8d417889c0ef2ab4c264693724d7153367b542348399
s390x
pam-1.5.1-23.el9_4.s390x.rpm SHA-256: 64cb92b469d37dbf701d9dc1e8657961a69c8145de39ae18f4b7c4bb1c17a76f
pam-debuginfo-1.5.1-23.el9_4.s390x.rpm SHA-256: 2e902b1909490c327e63923693db6999d2240174c3040cca65d6f9647a3f216c
pam-debuginfo-1.5.1-23.el9_4.s390x.rpm SHA-256: 2e902b1909490c327e63923693db6999d2240174c3040cca65d6f9647a3f216c
pam-debugsource-1.5.1-23.el9_4.s390x.rpm SHA-256: ab39dbbe6624ba013521636083700bd89092ab41bcd01d3fc630d0d08dd12c8c
pam-debugsource-1.5.1-23.el9_4.s390x.rpm SHA-256: ab39dbbe6624ba013521636083700bd89092ab41bcd01d3fc630d0d08dd12c8c
pam-devel-1.5.1-23.el9_4.s390x.rpm SHA-256: 2821ccff0851a1875fbb0a96aa652d3a3ef0ec62bf8e19d400f1b980a82c70c9
pam-docs-1.5.1-23.el9_4.s390x.rpm SHA-256: 382e96a672b3da0cb1f6e2acb0f20a8548481335e1e74a1c84626266c2125b6e

Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.4

SRPM
pam-1.5.1-23.el9_4.src.rpm SHA-256: f791b5c9aaf750b8108b8d417889c0ef2ab4c264693724d7153367b542348399
ppc64le
pam-1.5.1-23.el9_4.ppc64le.rpm SHA-256: e97836fca8854491ec9ae8e0ce01712284400a271bddd46dd14d2dbabb82ebdc
pam-debuginfo-1.5.1-23.el9_4.ppc64le.rpm SHA-256: cecdeda65307a02363329939db6c7f13e6ec79588b75d9b13ae801aa4a1a7cc3
pam-debuginfo-1.5.1-23.el9_4.ppc64le.rpm SHA-256: cecdeda65307a02363329939db6c7f13e6ec79588b75d9b13ae801aa4a1a7cc3
pam-debugsource-1.5.1-23.el9_4.ppc64le.rpm SHA-256: fe6af4730db9e16d9daf05889351471023370f1762096563497a657ea98cdfc8
pam-debugsource-1.5.1-23.el9_4.ppc64le.rpm SHA-256: fe6af4730db9e16d9daf05889351471023370f1762096563497a657ea98cdfc8
pam-devel-1.5.1-23.el9_4.ppc64le.rpm SHA-256: b4ced8006f7ad26387d6c8b4fadae9ad68349762095045edb45415de6854a2f5
pam-docs-1.5.1-23.el9_4.ppc64le.rpm SHA-256: fc211770bfa034fae473e9b21c0e9563727dd207113861741f10d9d3c317f15b

Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.4

SRPM
pam-1.5.1-23.el9_4.src.rpm SHA-256: f791b5c9aaf750b8108b8d417889c0ef2ab4c264693724d7153367b542348399
aarch64
pam-1.5.1-23.el9_4.aarch64.rpm SHA-256: 847c541334b8570cd9c5a39666c899e6ab96a708ad2f5a4ba8cd89429242b5fd
pam-debuginfo-1.5.1-23.el9_4.aarch64.rpm SHA-256: 8464b37e647eb0df457d7ede2a7dfe18fdc88d976e0359647e7149476280c1eb
pam-debuginfo-1.5.1-23.el9_4.aarch64.rpm SHA-256: 8464b37e647eb0df457d7ede2a7dfe18fdc88d976e0359647e7149476280c1eb
pam-debugsource-1.5.1-23.el9_4.aarch64.rpm SHA-256: 566541e94107493dfa7a8c240f7de3c4381194438e0acba9835f01753fed1093
pam-debugsource-1.5.1-23.el9_4.aarch64.rpm SHA-256: 566541e94107493dfa7a8c240f7de3c4381194438e0acba9835f01753fed1093
pam-devel-1.5.1-23.el9_4.aarch64.rpm SHA-256: 6bdd43b63d49c5913ff621372fbfca97745a045533938c26de7bfdf806de56ea
pam-docs-1.5.1-23.el9_4.aarch64.rpm SHA-256: 7baf54ff37c9ce1a1ba47c9b0951185ab19f44e0ee27c01d6f15f6b7855a8bba

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.4

SRPM
pam-1.5.1-23.el9_4.src.rpm SHA-256: f791b5c9aaf750b8108b8d417889c0ef2ab4c264693724d7153367b542348399
ppc64le
pam-1.5.1-23.el9_4.ppc64le.rpm SHA-256: e97836fca8854491ec9ae8e0ce01712284400a271bddd46dd14d2dbabb82ebdc
pam-debuginfo-1.5.1-23.el9_4.ppc64le.rpm SHA-256: cecdeda65307a02363329939db6c7f13e6ec79588b75d9b13ae801aa4a1a7cc3
pam-debuginfo-1.5.1-23.el9_4.ppc64le.rpm SHA-256: cecdeda65307a02363329939db6c7f13e6ec79588b75d9b13ae801aa4a1a7cc3
pam-debugsource-1.5.1-23.el9_4.ppc64le.rpm SHA-256: fe6af4730db9e16d9daf05889351471023370f1762096563497a657ea98cdfc8
pam-debugsource-1.5.1-23.el9_4.ppc64le.rpm SHA-256: fe6af4730db9e16d9daf05889351471023370f1762096563497a657ea98cdfc8
pam-devel-1.5.1-23.el9_4.ppc64le.rpm SHA-256: b4ced8006f7ad26387d6c8b4fadae9ad68349762095045edb45415de6854a2f5
pam-docs-1.5.1-23.el9_4.ppc64le.rpm SHA-256: fc211770bfa034fae473e9b21c0e9563727dd207113861741f10d9d3c317f15b

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4

SRPM
pam-1.5.1-23.el9_4.src.rpm SHA-256: f791b5c9aaf750b8108b8d417889c0ef2ab4c264693724d7153367b542348399
x86_64
pam-1.5.1-23.el9_4.i686.rpm SHA-256: ffc8a49ef51eecbb1f19c28b43c62f6c65c63abb000af88d579f9401143a7ab5
pam-1.5.1-23.el9_4.x86_64.rpm SHA-256: b2a90a84512ccf6acd4a16d48c65b689fd5e44bd545231dffdb8525d783beb94
pam-debuginfo-1.5.1-23.el9_4.i686.rpm SHA-256: 32908ab97d201482c8e0b1cf337bba2676b7a0fd30f6ab58b48e9edc4549dca6
pam-debuginfo-1.5.1-23.el9_4.i686.rpm SHA-256: 32908ab97d201482c8e0b1cf337bba2676b7a0fd30f6ab58b48e9edc4549dca6
pam-debuginfo-1.5.1-23.el9_4.x86_64.rpm SHA-256: e516a1b2b979929adf8299d27019041ea8badbdc434816493fcf608bc2f47412
pam-debuginfo-1.5.1-23.el9_4.x86_64.rpm SHA-256: e516a1b2b979929adf8299d27019041ea8badbdc434816493fcf608bc2f47412
pam-debugsource-1.5.1-23.el9_4.i686.rpm SHA-256: 1b768154fd91212ab80f5724fde0bb4921d202b1a086aa99b18959ca4960e716
pam-debugsource-1.5.1-23.el9_4.i686.rpm SHA-256: 1b768154fd91212ab80f5724fde0bb4921d202b1a086aa99b18959ca4960e716
pam-debugsource-1.5.1-23.el9_4.x86_64.rpm SHA-256: 7003e47ebe8b441219ac2d04e61335e7e8dca01ef50a11868d794c25deafb123
pam-debugsource-1.5.1-23.el9_4.x86_64.rpm SHA-256: 7003e47ebe8b441219ac2d04e61335e7e8dca01ef50a11868d794c25deafb123
pam-devel-1.5.1-23.el9_4.i686.rpm SHA-256: 6ab491de47fcb63f6d50685a13587f67f5f7ca4b7095ae80a52f54289bd7c0cf
pam-devel-1.5.1-23.el9_4.x86_64.rpm SHA-256: 68f5fd880341c068f1c391c9963f5e891f63a0a7f187487e7e4dc4186b77e038
pam-docs-1.5.1-23.el9_4.x86_64.rpm SHA-256: 71a2c584733414a6acae2aee9fb55caf4ac727304c42c8a32e27618fa8b78bea

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.4

SRPM
pam-1.5.1-23.el9_4.src.rpm SHA-256: f791b5c9aaf750b8108b8d417889c0ef2ab4c264693724d7153367b542348399
aarch64
pam-1.5.1-23.el9_4.aarch64.rpm SHA-256: 847c541334b8570cd9c5a39666c899e6ab96a708ad2f5a4ba8cd89429242b5fd
pam-debuginfo-1.5.1-23.el9_4.aarch64.rpm SHA-256: 8464b37e647eb0df457d7ede2a7dfe18fdc88d976e0359647e7149476280c1eb
pam-debuginfo-1.5.1-23.el9_4.aarch64.rpm SHA-256: 8464b37e647eb0df457d7ede2a7dfe18fdc88d976e0359647e7149476280c1eb
pam-debugsource-1.5.1-23.el9_4.aarch64.rpm SHA-256: 566541e94107493dfa7a8c240f7de3c4381194438e0acba9835f01753fed1093
pam-debugsource-1.5.1-23.el9_4.aarch64.rpm SHA-256: 566541e94107493dfa7a8c240f7de3c4381194438e0acba9835f01753fed1093
pam-devel-1.5.1-23.el9_4.aarch64.rpm SHA-256: 6bdd43b63d49c5913ff621372fbfca97745a045533938c26de7bfdf806de56ea
pam-docs-1.5.1-23.el9_4.aarch64.rpm SHA-256: 7baf54ff37c9ce1a1ba47c9b0951185ab19f44e0ee27c01d6f15f6b7855a8bba

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.4

SRPM
pam-1.5.1-23.el9_4.src.rpm SHA-256: f791b5c9aaf750b8108b8d417889c0ef2ab4c264693724d7153367b542348399
s390x
pam-1.5.1-23.el9_4.s390x.rpm SHA-256: 64cb92b469d37dbf701d9dc1e8657961a69c8145de39ae18f4b7c4bb1c17a76f
pam-debuginfo-1.5.1-23.el9_4.s390x.rpm SHA-256: 2e902b1909490c327e63923693db6999d2240174c3040cca65d6f9647a3f216c
pam-debuginfo-1.5.1-23.el9_4.s390x.rpm SHA-256: 2e902b1909490c327e63923693db6999d2240174c3040cca65d6f9647a3f216c
pam-debugsource-1.5.1-23.el9_4.s390x.rpm SHA-256: ab39dbbe6624ba013521636083700bd89092ab41bcd01d3fc630d0d08dd12c8c
pam-debugsource-1.5.1-23.el9_4.s390x.rpm SHA-256: ab39dbbe6624ba013521636083700bd89092ab41bcd01d3fc630d0d08dd12c8c
pam-devel-1.5.1-23.el9_4.s390x.rpm SHA-256: 2821ccff0851a1875fbb0a96aa652d3a3ef0ec62bf8e19d400f1b980a82c70c9
pam-docs-1.5.1-23.el9_4.s390x.rpm SHA-256: 382e96a672b3da0cb1f6e2acb0f20a8548481335e1e74a1c84626266c2125b6e

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility