========================================================================== Ubuntu Security Notice USN-7580-1 June 18, 2025 pam vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.04 - Ubuntu 24.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: PAM could be made to run programs as an administrator. Software Description: - pam: Pluggable Authentication Modules Details: Olivier BAL-PETRE discovered that the PAM pam_namespace module incorrectly handled user-controlled paths. In environments where pam_namespace is used, a local attacker could possibly use this issue to escalate their privileges to root. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.04 libpam-modules 1.5.3-7ubuntu4.3 Ubuntu 24.10 libpam-modules 1.5.3-7ubuntu2.3 Ubuntu 24.04 LTS libpam-modules 1.5.3-5ubuntu5.4 Ubuntu 22.04 LTS libpam-modules 1.4.0-11ubuntu2.6 After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7580-1 CVE-2025-6020 Package Information: https://launchpad.net/ubuntu/+source/pam/1.5.3-7ubuntu4.3 https://launchpad.net/ubuntu/+source/pam/1.5.3-7ubuntu2.3 https://launchpad.net/ubuntu/+source/pam/1.5.3-5ubuntu5.4 https://launchpad.net/ubuntu/+source/pam/1.4.0-11ubuntu2.6