Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:15106 - Security Advisory
Issued:
2025-09-03
Updated:
2025-09-03

RHSA-2025:15106 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: pam security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for pam is now available for Red Hat Enterprise Linux 7 Extended Lifecycle Support.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Pluggable Authentication Modules (PAM) provide a system to set up authentication policies without the need to recompile programs to handle authentication.

Security Fix(es):

  • linux-pam: Incomplete fix for CVE-2025-6020 (CVE-2025-8941)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server - Extended Life Cycle Support 7 x86_64
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7 s390x
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7 ppc64
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7 ppc64le

Fixes

  • BZ - 2388220 - CVE-2025-8941 linux-pam: Incomplete fix for CVE-2025-6020

CVEs

  • CVE-2025-8941

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server - Extended Life Cycle Support 7

SRPM
pam-1.1.8-23.el7_9.2.src.rpm SHA-256: 856adfcd61c5f250ac9cd733c77f3a2548b37a5fb4c61d4733ac481fa60e0f96
x86_64
pam-1.1.8-23.el7_9.2.i686.rpm SHA-256: 5a2fe53957785cfb7f51bbcd1d35570bb5f19ce787aa5da61133ced893203787
pam-1.1.8-23.el7_9.2.x86_64.rpm SHA-256: 8a3f0c21c07d2d272b8594a7efaebd32416a8d156d98a133238369fd66cb3ba0
pam-debuginfo-1.1.8-23.el7_9.2.i686.rpm SHA-256: 8519a7b522e5cbbd75eee0d63c6a375d5ed11179f3d6ac2bc9d0acb3a351eccd
pam-debuginfo-1.1.8-23.el7_9.2.x86_64.rpm SHA-256: fb51ac846d7f9813bd609a72b0405c2684cd6f40866eea89719d7716c425bf67
pam-devel-1.1.8-23.el7_9.2.i686.rpm SHA-256: e402c2e3f516480d55675b838ced18411739199719769ecd47ccc5d549da47ca
pam-devel-1.1.8-23.el7_9.2.x86_64.rpm SHA-256: d134bcc4e2a8c87b94617064e2c46b4b88d2c594d76b7d9bc5c1595e457921aa

Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7

SRPM
pam-1.1.8-23.el7_9.2.src.rpm SHA-256: 856adfcd61c5f250ac9cd733c77f3a2548b37a5fb4c61d4733ac481fa60e0f96
s390x
pam-1.1.8-23.el7_9.2.s390.rpm SHA-256: ed2048367176faffaaeafe220405a2923159947d4a44473200d82cb420bc71fc
pam-1.1.8-23.el7_9.2.s390x.rpm SHA-256: 229f1e813058eb0b78d1a19dec277abb476d1c2dd8629cd9ee9f1035234bc27f
pam-debuginfo-1.1.8-23.el7_9.2.s390.rpm SHA-256: b4b0903fc670a33a34480b311f0236a973df5720dc41b8762d58c3b9c52cb8f7
pam-debuginfo-1.1.8-23.el7_9.2.s390x.rpm SHA-256: 52d973c68c68f03c22a03c9fa69db1dba7bd1ab023c6fe1ebe5297bc2ab0876c
pam-devel-1.1.8-23.el7_9.2.s390.rpm SHA-256: a89fe189a45e4dfb1c26327aa04111c21ce2fee807333a1de3f6c287570a5c36
pam-devel-1.1.8-23.el7_9.2.s390x.rpm SHA-256: 94cd2555fff4287a6e8d12002e5509dbd7038873c7f02fc20bb236094fc5a0e5

Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7

SRPM
pam-1.1.8-23.el7_9.2.src.rpm SHA-256: 856adfcd61c5f250ac9cd733c77f3a2548b37a5fb4c61d4733ac481fa60e0f96
ppc64
pam-1.1.8-23.el7_9.2.ppc.rpm SHA-256: 962ff12b98a378d20b64966feb65c226cd0fcb269bd0028fbbc8a33ee9e0ed72
pam-1.1.8-23.el7_9.2.ppc64.rpm SHA-256: e8278b6a42aa3288b1164fa2fa3faf51887fbe311e97c961cf65a78c14513f05
pam-debuginfo-1.1.8-23.el7_9.2.ppc.rpm SHA-256: c10d9d6b9f40d76a87736f58c9cd9bb6d41dc7f4024afa10d93cc3228a20f439
pam-debuginfo-1.1.8-23.el7_9.2.ppc64.rpm SHA-256: 3abfd8165812b9fb411851060905e6ab997fad04b16625c05f969c4bd2d769e6
pam-devel-1.1.8-23.el7_9.2.ppc.rpm SHA-256: ff7d30c5e7af260be7d6cc72b69f2d8f0563237149047e5a855eba45c7d2e037
pam-devel-1.1.8-23.el7_9.2.ppc64.rpm SHA-256: 2681b9f6d65943ab9890feaf47b3f00a7e9879751aac6bb8ebcbe15af0f0fd2c

Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7

SRPM
pam-1.1.8-23.el7_9.2.src.rpm SHA-256: 856adfcd61c5f250ac9cd733c77f3a2548b37a5fb4c61d4733ac481fa60e0f96
ppc64le
pam-1.1.8-23.el7_9.2.ppc64le.rpm SHA-256: 7751955e2fafbd29bcaf3476ea167100ec17fafa1116ecf075ac0f8cf122575a
pam-debuginfo-1.1.8-23.el7_9.2.ppc64le.rpm SHA-256: 816e42f398dd6952a18e4dad34ddb01baf4fb3c78da5081c0b1a93bbbb1478ca
pam-devel-1.1.8-23.el7_9.2.ppc64le.rpm SHA-256: b948343620b24074a945faefae56bd8647fd1545a5a718fa92b78a79ad446442

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility