From patchwork Fri Oct 2 11:23:27 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Adolf Belka X-Patchwork-Id: 10301 Return-Path: Received: from mail01.ipfire.org (mail01.haj.ipfire.org [172.28.1.202]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (Client CN "mail01.haj.ipfire.org", Issuer "YR2" (not verified)) by web04.haj.ipfire.org (Postfix) with ESMTPS id 4hx5yF15TLz3wrL for ; Fri, 02 Oct 2026 11:23:49 +0000 (UTC) Received: from mail02.haj.ipfire.org (mail02.haj.ipfire.org [IPv6:2001:678:b28::201]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (Client CN "mail02.haj.ipfire.org", Issuer "YE1" (not verified)) by mail01.ipfire.org (Postfix) with ESMTPS id 4hx5yC4Wfhz81d for ; Fri, 02 Oct 2026 11:23:47 +0000 (UTC) Received: from mail02.haj.ipfire.org (localhost [IPv6:::1]) by mail02.haj.ipfire.org (Postfix) with ESMTP id 4hx5y80mVzz37Jl for ; Fri, 02 Oct 2026 11:23:44 +0000 (UTC) X-Original-To: development@lists.ipfire.org Received: from mail01.ipfire.org (mail01.haj.ipfire.org [IPv6:2001:678:b28::25]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (Client CN "mail01.haj.ipfire.org", Issuer "YR2" (not verified)) by mail02.haj.ipfire.org (Postfix) with ESMTPS id 4hx5y11bTGz37FB for ; Fri, 02 Oct 2026 11:23:37 +0000 (UTC) Received: from [127.0.0.1] (localhost [127.0.0.1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by mail01.ipfire.org (Postfix) with ESMTPSA id 4hx5y06vc2z4Xx; Fri, 02 Oct 2026 11:23:36 +0000 (UTC) DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=ipfire.org; s=202003ed25519; t=1790940217; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=1zwnYvhCrqjGjpVEEdIzIJixtM4O7bLkRP6RVab9z2g=; b=9eSfaEOziIFqyeZr9WW0l7+cgZxl//OkbnQkeHb34va+X5WDm/lWu7RZ5PbtkcxZuKh3sB X8qIpKbXvL+Y8VDA== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ipfire.org; s=202003rsa; t=1790940217; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=1zwnYvhCrqjGjpVEEdIzIJixtM4O7bLkRP6RVab9z2g=; b=J9IjPkeC0inwr444EdaOPIMnYw5ORnzR9tcMyVo+8mlCZUyGf6WhxK0/q6MLqgJHQ06Cfu i8Lxjz2JIGlVMdGHdzQ9Vgvjs+ZI9q79KC/pk3D5JZoCz86zSWdgfqlxHS3LFeWVfAc3r3 ctqr/b+0oMGiEGaLj+jLFbCQ1MUI06fOoHIGNqnFgQxRXHjnVdKtOHSWeunFrbJaITMxe4 IVx2q2BxvJ0V6tHjNwmPPsVwATO3T/40MaMAnYYbK5ArIFq1jrNaYkqyfEc5R7JTiX51VJ 8cXIu+rbnwIyBQ53JR1Tad+GVGsZsPh+bi+dIzi2bPMRda+D5AvDBVmRTLi5ew== From: Adolf Belka To: development@lists.ipfire.org Cc: Adolf Belka Subject: [PATCH] pam: Update to version 1.7.3 Date: Fri, 2 Oct 2026 13:23:27 +0200 Message-ID: <20261002112330.3568361-10-adolf.belka@ipfire.org> In-Reply-To: <20261002112330.3568361-1-adolf.belka@ipfire.org> References: <20261002112330.3568361-1-adolf.belka@ipfire.org> Precedence: list List-Id: List-Subscribe: , List-Unsubscribe: , List-Post: List-Help: Sender: Mail-Followup-To: MIME-Version: 1.0 - Update from version 1.7.2 to 1.7.3 - Update of rootfile - Changelog 1.7.3 * pam_unix: removed support for creating new DES/bigcrypt hashed passwords. Login with existing DES/bigcrypt passwords is still possible. * pam_unix: changed the default hash algorithm from DES to SHA512. * pam_unix: always use unix_update helper if SELinux is enabled. * pam_unix: fixed option parsing that could silently ignore "quiet" and "minlen=" depending on configuration line order. * pam_access: fixed matching of fully qualified usernames. * pam_env: fixed buffer allocation that could result in insufficient space. * pam_faillock: fixed tally loss under concurrent auth failures that could allow the deny= threshold to be bypassed. * pam_faillock: added logging when preauth denies access to a locked account. * pam_group: fixed out-of-bounds read in wildcard matching. * pam_limits: fixed maxlogins/maxsyslogins limits that could incorrectly deny login. * pam_namespace: fixed resource leaks on configuration parse errors. * pam_pwhistory: allow earlier passwords when remember count is reduced. * pam_selinux: fixed memory leaks and corrected swapped arguments in log messages. * pam_sepermit: fixed crash on malformed config lines, hardened lock file handling, and fixed leaking file descriptors on exec. * pam_succeed_if: fixed broken ruser matching and prevented logging unknown user names in plaintext. * pam_time: fixed out-of-bounds read in wildcard matching, fixed day-of-week parsing, and ignore rules with malformed time fields. * pam_umask: validate umask, pri and ulimit values in GECOS. * pam_userdb: fixed password comparison timing leak. * Multiple minor bug fixes, build fixes, portability fixes, documentation improvements, and translation updates. Signed-off-by: Adolf Belka --- config/rootfiles/common/pam | 5 +++-- lfs/pam | 4 ++-- 2 files changed, 5 insertions(+), 4 deletions(-) diff --git a/config/rootfiles/common/pam b/config/rootfiles/common/pam index 18826b21e..5fd9332cc 100644 --- a/config/rootfiles/common/pam +++ b/config/rootfiles/common/pam @@ -82,8 +82,6 @@ usr/lib/libpamc.so.0.82.1 #usr/share/locale/am #usr/share/locale/am/LC_MESSAGES #usr/share/locale/am/LC_MESSAGES/Linux-PAM.mo -#usr/share/locale/ar -#usr/share/locale/ar/LC_MESSAGES #usr/share/locale/ar/LC_MESSAGES/Linux-PAM.mo #usr/share/locale/as #usr/share/locale/as/LC_MESSAGES @@ -143,6 +141,9 @@ usr/lib/libpamc.so.0.82.1 #usr/share/locale/it/LC_MESSAGES/Linux-PAM.mo #usr/share/locale/ja/LC_MESSAGES/Linux-PAM.mo #usr/share/locale/ka/LC_MESSAGES/Linux-PAM.mo +#usr/share/locale/kab +#usr/share/locale/kab/LC_MESSAGES +#usr/share/locale/kab/LC_MESSAGES/Linux-PAM.mo #usr/share/locale/kk/LC_MESSAGES/Linux-PAM.mo #usr/share/locale/km #usr/share/locale/km/LC_MESSAGES diff --git a/lfs/pam b/lfs/pam index e2d635480..85c06a65d 100644 --- a/lfs/pam +++ b/lfs/pam @@ -24,7 +24,7 @@ include Config -VER = 1.7.2 +VER = 1.7.3 THISAPP = Linux-PAM-$(VER) DL_FILE = $(THISAPP).tar.xz @@ -45,7 +45,7 @@ objects = $(DL_FILE) $(DL_FILE) = $(DL_FROM)/$(DL_FILE) -$(DL_FILE)_BLAKE2 = d7ebfac4393af3f889fef973946f1e6d60f118f2e048448708c5fdf0ef7fa7780945cda3b0abf6e0e2e15bbc2dd23be52389efabd00647381b3bc971f1aadcd8 +$(DL_FILE)_BLAKE2 = 2476e5b08f8e4c3e013f8ee22d858da79e9074160d396b504400c1f7ee490df9b432b226d18ae58e6f5c77a0a31709d363b76c800cd86953237f7e534a317358 install : $(TARGET)