Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:10354 - Security Advisory
Issued:
2025-07-07
Updated:
2025-07-07

RHSA-2025:10354 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: pam security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for pam is now available for Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Pluggable Authentication Modules (PAM) provide a system to set up authentication policies without the need to recompile programs to handle authentication.

Security Fix(es):

  • linux-pam: Linux-pam directory Traversal (CVE-2025-6020)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.0 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0 x86_64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.0 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.0 s390x

Fixes

  • BZ - 2372512 - CVE-2025-6020 linux-pam: Linux-pam directory Traversal

CVEs

  • CVE-2025-6020

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.0

SRPM
pam-1.5.1-9.el9_0.2.src.rpm SHA-256: 43ab283e24953f8d67e27eb64112f990190b19c6727d684e8da04aff129464e8
ppc64le
pam-1.5.1-9.el9_0.2.ppc64le.rpm SHA-256: a02ef23d1ba2552102a0f74cd95bb9856620f856ced40499d61eb8fcd71bc7a1
pam-debuginfo-1.5.1-9.el9_0.2.ppc64le.rpm SHA-256: 70663ee62b4b99786eb02f49daef349217299c94ae9d5f3c7ef9cc42dc43d828
pam-debuginfo-1.5.1-9.el9_0.2.ppc64le.rpm SHA-256: 70663ee62b4b99786eb02f49daef349217299c94ae9d5f3c7ef9cc42dc43d828
pam-debugsource-1.5.1-9.el9_0.2.ppc64le.rpm SHA-256: 6da6fa20f87d6d222aa1262c4cd10dc4c59d8d1ab8126ccb06b4dbeb4f612cf8
pam-debugsource-1.5.1-9.el9_0.2.ppc64le.rpm SHA-256: 6da6fa20f87d6d222aa1262c4cd10dc4c59d8d1ab8126ccb06b4dbeb4f612cf8
pam-devel-1.5.1-9.el9_0.2.ppc64le.rpm SHA-256: a7099fa8e83585b69858cc14de249bf58fae821854af694db10d2bee9599214c
pam-docs-1.5.1-9.el9_0.2.ppc64le.rpm SHA-256: d7a80f3a15cfda35b91c93e5bd69a73e16bf72e503fc7a5c7cc1fbe9e29a47c9

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0

SRPM
pam-1.5.1-9.el9_0.2.src.rpm SHA-256: 43ab283e24953f8d67e27eb64112f990190b19c6727d684e8da04aff129464e8
x86_64
pam-1.5.1-9.el9_0.2.i686.rpm SHA-256: 0779d1121d05a6633d43526ae4a9e8d2d48f3edb40d941143f54c59d2c7f3a6c
pam-1.5.1-9.el9_0.2.x86_64.rpm SHA-256: 694aa772dc589df1de1fb1d70136c4712277189188b6c44d061e19fe6e8bb7fb
pam-debuginfo-1.5.1-9.el9_0.2.i686.rpm SHA-256: 8446947ea49793066a4f6bbcf037fe313f0ca339ba5fc1953e1dd51c3d514874
pam-debuginfo-1.5.1-9.el9_0.2.i686.rpm SHA-256: 8446947ea49793066a4f6bbcf037fe313f0ca339ba5fc1953e1dd51c3d514874
pam-debuginfo-1.5.1-9.el9_0.2.x86_64.rpm SHA-256: 1c8fefe6016401ea9e8ddf69befd3d44f9ecfacb47f1553933b68eb0b19043ed
pam-debuginfo-1.5.1-9.el9_0.2.x86_64.rpm SHA-256: 1c8fefe6016401ea9e8ddf69befd3d44f9ecfacb47f1553933b68eb0b19043ed
pam-debugsource-1.5.1-9.el9_0.2.i686.rpm SHA-256: 0cfd52921718ba9c8065629f69b8f6b69da186cdc608656b086c1288c47a9b97
pam-debugsource-1.5.1-9.el9_0.2.i686.rpm SHA-256: 0cfd52921718ba9c8065629f69b8f6b69da186cdc608656b086c1288c47a9b97
pam-debugsource-1.5.1-9.el9_0.2.x86_64.rpm SHA-256: 0d3de59e8efe3103131e9fe42d9e1166ed57269640e2a3e317eb101f2c72ec8c
pam-debugsource-1.5.1-9.el9_0.2.x86_64.rpm SHA-256: 0d3de59e8efe3103131e9fe42d9e1166ed57269640e2a3e317eb101f2c72ec8c
pam-devel-1.5.1-9.el9_0.2.i686.rpm SHA-256: 85157aac1d30f83249bf48ad16df02f5dff1f051701d52563c0e48e6c6368c9a
pam-devel-1.5.1-9.el9_0.2.x86_64.rpm SHA-256: e14a87c8f72e6f551f9fb6a5e914f0512663d5339328107c0da57214fb07c2c1
pam-docs-1.5.1-9.el9_0.2.x86_64.rpm SHA-256: b24bf578ecdcee84d831e63e592121f1030a40da7863a762d3a96fdc73c43ee6

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.0

SRPM
pam-1.5.1-9.el9_0.2.src.rpm SHA-256: 43ab283e24953f8d67e27eb64112f990190b19c6727d684e8da04aff129464e8
aarch64
pam-1.5.1-9.el9_0.2.aarch64.rpm SHA-256: 8d1dde32ceab465f32e884bca72665b44ccb147096789ec4eafbb97526f9644a
pam-debuginfo-1.5.1-9.el9_0.2.aarch64.rpm SHA-256: 0ea26b1421f98c59da03161466fd2162967f4c35a11ba0fb59b49fd25f79f76d
pam-debuginfo-1.5.1-9.el9_0.2.aarch64.rpm SHA-256: 0ea26b1421f98c59da03161466fd2162967f4c35a11ba0fb59b49fd25f79f76d
pam-debugsource-1.5.1-9.el9_0.2.aarch64.rpm SHA-256: aa80e50e3567eef476a9b86f8e2f364a4720684799557aa32e3882305667dc80
pam-debugsource-1.5.1-9.el9_0.2.aarch64.rpm SHA-256: aa80e50e3567eef476a9b86f8e2f364a4720684799557aa32e3882305667dc80
pam-devel-1.5.1-9.el9_0.2.aarch64.rpm SHA-256: 1760649f0f0b0d2552d39f845b866b5c9458af7f056ef5898cb8177a8a23bb73
pam-docs-1.5.1-9.el9_0.2.aarch64.rpm SHA-256: e5a7ed94df59714bd38c409fe0209c2c16b18550d540be4c37070c102bb39a7c

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.0

SRPM
pam-1.5.1-9.el9_0.2.src.rpm SHA-256: 43ab283e24953f8d67e27eb64112f990190b19c6727d684e8da04aff129464e8
s390x
pam-1.5.1-9.el9_0.2.s390x.rpm SHA-256: 0be310e5831e733ad92ea30d7f7b234eb18b1d67ffe1e41f5af323afd268a05c
pam-debuginfo-1.5.1-9.el9_0.2.s390x.rpm SHA-256: 5f4e7b8abbce3f0e14490d89df67b72ef704fdc28d19c1f9316ca80e7180fdbc
pam-debuginfo-1.5.1-9.el9_0.2.s390x.rpm SHA-256: 5f4e7b8abbce3f0e14490d89df67b72ef704fdc28d19c1f9316ca80e7180fdbc
pam-debugsource-1.5.1-9.el9_0.2.s390x.rpm SHA-256: a4f624e47c4bb20730c0d514bd30d7270abaa52dd4845615145d79db54fe70c3
pam-debugsource-1.5.1-9.el9_0.2.s390x.rpm SHA-256: a4f624e47c4bb20730c0d514bd30d7270abaa52dd4845615145d79db54fe70c3
pam-devel-1.5.1-9.el9_0.2.s390x.rpm SHA-256: f8cc6c07f292c8ced68a87800b12df164ed5870d37e2009ccca218457f738464
pam-docs-1.5.1-9.el9_0.2.s390x.rpm SHA-256: 2bf8bded154bcf2d6f687aed90efba0471d20d84eba8be2e1e8fdf4bc9013359

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility