{"id":"USN-8688-2","summary":"pam vulnerability","details":"USN-8688-1 fixed a vulnerability in PAM. This update provides the\ncorresponding fix for PAM on Ubuntu 26.04 LTS.\n\nOriginal advisory details:\n\n Juthawong Naisanguansee discovered that PAM incorrectly cleared failed\n login attempt records when certain services invoked the account phase\n without first performing authentication. An attacker could possibly use\n this issue to reset failed login counters, resulting in authentication\n lockout restrictions being bypassed.","modified":"2026-09-02T02:30:03.001561583Z","published":"2026-09-01T15:43:56Z","references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-8688-2"},{"type":"REPORT","url":"https://launchpad.net/bugs/2164901"}],"affected":[{"package":{"name":"pam","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/pam?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.7.0-5ubuntu3.2"}]}],"versions":["1.7.0-5ubuntu2","1.7.0-5ubuntu3","1.7.0-5ubuntu3.1"],"ecosystem_specific":{"binaries":[{"binary_name":"libpam-modules","binary_version":"1.7.0-5ubuntu3.2"},{"binary_name":"libpam-modules-bin","binary_version":"1.7.0-5ubuntu3.2"},{"binary_name":"libpam-runtime","binary_version":"1.7.0-5ubuntu3.2"},{"binary_name":"libpam0g","binary_version":"1.7.0-5ubuntu3.2"}],"availability":"No subscription required"},"database_specific":{"cves_map":{"cves":[],"ecosystem":"Ubuntu:26.04:LTS"},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8688-2.json"}}],"schema_version":"1.9.0"}