Bug 34219 - pam new security issue CVE-2024-10041
Summary: pam new security issue CVE-2024-10041
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2025-04-22 14:29 CEST by Nicolas Salguero
Modified: 2025-05-05 06:59 CEST (History)
3 users (show)

See Also:
Source RPM: pam-1.5.2-5.1.mga9.src.rpm
CVE: CVE-2024-10041
Status comment:


Attachments

Description Nicolas Salguero 2025-04-22 14:29:08 CEST
openSUSE has issued an advisory on April 17:
https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/S3CBZDTRIQZKAUHHWFBJKJ7PYA7BPARL/
Comment 1 Nicolas Salguero 2025-04-22 14:30:23 CEST
Upstream fix: https://github.com/linux-pam/linux-pam/commit/b3020da7da384d769f27a8713257fbe1001878be

CVE: (none) => CVE-2024-10041
Status comment: (none) => Patch available from upstream and openSUSE
Whiteboard: (none) => MGA9TOO
Source RPM: (none) => pam-1.5.2-9.mga10.src.rpm, pam-1.5.2-5.1.mga9.src.rpm

Comment 2 Lewis Smith 2025-04-23 11:02:48 CEST
Different packagers commit this, so assigning it globally.

Assignee: bugsquad => pkg-bugs

Comment 3 Nicolas Salguero 2025-04-29 14:52:40 CEST
Suggested advisory:
========================

The updated packages fix a security vulnerability:

libpam vulnerable to read hashed password. (CVE-2024-10041)

References:
https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/S3CBZDTRIQZKAUHHWFBJKJ7PYA7BPARL/
========================

Updated packages in core/updates_testing:
========================
lib(64)pam0-1.5.2-5.2.mga9
lib(64)pam-devel-1.5.2-5.2.mga9
pam-1.5.2-5.2.mga9
pam-doc-1.5.2-5.2.mga9

from SRPM:
pam-1.5.2-5.2.mga9.src.rpm

Whiteboard: MGA9TOO => (none)
Status comment: Patch available from upstream and openSUSE => (none)
Assignee: pkg-bugs => qa-bugs
Status: NEW => ASSIGNED
Source RPM: pam-1.5.2-9.mga10.src.rpm, pam-1.5.2-5.1.mga9.src.rpm => pam-1.5.2-5.1.mga9.src.rpm
Version: Cauldron => 9

katnatek 2025-04-29 19:43:53 CEST

Keywords: (none) => advisory

Comment 4 Herman Viaene 2025-05-01 14:15:48 CEST
MGA9-64 Plasma Wayland on Compaq H000SB.
No installation issues.
Ref bugs 32746 and 16212, so I can su to root, start MCC and get access.
Good to go.

Whiteboard: (none) => MGA9-64-OK
CC: (none) => herman.viaene

Comment 5 Thomas Andrews 2025-05-02 01:11:22 CEST
Validating.

CC: (none) => andrewsfarm, sysadmin-bugs
Keywords: (none) => validated_update

Comment 6 Mageia Robot 2025-05-05 06:59:17 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2025-0149.html

Status: ASSIGNED => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.