USN-8688-2

Source
https://ubuntu.com/security/notices/USN-8688-2
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8688-2.json
JSON Data
https://api.osv.dev/v1/vulns/USN-8688-2
Published
2026-09-01T15:43:56Z
Modified
2026-09-02T02:30:03.001561583Z
Summary
pam vulnerability
Details

USN-8688-1 fixed a vulnerability in PAM. This update provides the corresponding fix for PAM on Ubuntu 26.04 LTS.

Original advisory details:

Juthawong Naisanguansee discovered that PAM incorrectly cleared failed login attempt records when certain services invoked the account phase without first performing authentication. An attacker could possibly use this issue to reset failed login counters, resulting in authentication lockout restrictions being bypassed.

References

Affected packages

Ubuntu:26.04:LTS / pam

Package

Name
pam
Purl
pkg:deb/ubuntu/pam?arch=source&distro=resolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.7.0-5ubuntu3.2

Affected versions

1.*
1.7.0-5ubuntu2
1.7.0-5ubuntu3
1.7.0-5ubuntu3.1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "1.7.0-5ubuntu3.2",
            "binary_name": "libpam-modules"
        },
        {
            "binary_version": "1.7.0-5ubuntu3.2",
            "binary_name": "libpam-modules-bin"
        },
        {
            "binary_version": "1.7.0-5ubuntu3.2",
            "binary_name": "libpam-runtime"
        },
        {
            "binary_version": "1.7.0-5ubuntu3.2",
            "binary_name": "libpam0g"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8688-2.json"
cves_map
{
    "ecosystem": "Ubuntu:26.04:LTS",
    "cves": []
}