Home / mailings [USN-8688-2] PAM vulnerability
Posted on 01 September 2026
Ubuntu Security==========================================================================Ubuntu Security Notice USN-8688-2
September 01, 2026
pam vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 26.04 LTS
Summary:
A system hardening measure could be bypassed.
Software Description:
- pam: Pluggable Authentication Modules
Details:
USN-8688-1 fixed a vulnerability in PAM. This update provides the
corresponding fix for PAM on Ubuntu 26.04 LTS.
Original advisory details:
Juthawong Naisanguansee discovered that PAM incorrectly cleared failed
login attempt records when certain services invoked the account phase
without first performing authentication. An attacker could possibly use
this issue to reset failed login counters, resulting in authentication
lockout restrictions being bypassed.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 26.04 LTS
libpam-modules 1.7.0-5ubuntu3.2
libpam-modules-bin 1.7.0-5ubuntu3.2
libpam-runtime 1.7.0-5ubuntu3.2
libpam0g 1.7.0-5ubuntu3.2
libpam0g-dev 1.7.0-5ubuntu3.2
After a standard system update you need to reboot your computer to make
all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-8688-2
https://ubuntu.com/security/notices/USN-8688-1
https://launchpad.net/bugs/2164901
Package Information:
https://launchpad.net/ubuntu/+source/pam/1.7.0-5ubuntu3.2
--===============9219090187778668457==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
