USN-6588-1: PAM vulnerability
17 January 2024
PAM could be made to stop responding if it opened a specially crafted file.
Releases
Packages
- pam - Pluggable Authentication Modules
Details
Matthias Gerstner discovered that the PAM pam_namespace module incorrectly
handled special files when performing directory checks. A local attacker
could possibly use this issue to cause PAM to stop responding, resulting in
a denial of service.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 23.10
Ubuntu 23.04
Ubuntu 22.04
Ubuntu 20.04
In general, a standard system update will make all the necessary changes.
References
Related notices
- USN-6588-2: libpam-modules-bin, libpam0g, libpam-doc, pam, libpam0g-dev, libpam-cracklib, libpam-runtime, libpam-modules