Le dimanche 3 août 2025, 14:05:33 heure d’été d’Europe centrale Salvatore Bonaccorso a écrit : > On Sun, Aug 03, 2025 at 01:22:13PM +0200, Bastien Roucaries wrote: > > Source: pam > > Version: 1.7.0-5 > > Severity: grave > > Justification: may breaks the whole system (loggin) > > X-Debbugs-CC: [email protected] > > X-Debbugs-CC: Debian Security Team <[email protected]> > > > > Hi, > > > > Following fix of CVE-2024-10041 pam now use /usr/sbin/unix_chkpwd > > inconditionnaly > > > > If someone use apparmor login or user then login will fail, may be some > > time latter due to expired password or other unix configuration > > > > see https://bugzilla.opensuse.org/show_bug.cgi?id=1219139 > > https://salsa.debian.org/apparmor-team/apparmor/-/commit/243162ca2938b3917 > > 24f547596787c7f77d1fc5f > > > > I order to be in the safe side could you add Breaks: apparmor-profiles (<< > > 4.1.0-1~) or may be Pre-Depends: > > > > apparmor need to be updated before pam. > > > > I know it is late in the release cycle, but I just detected trying to > > debug stuff for pam. > > > > Maybe postone > > Should this be reassigned to src:apparmor instread then and marked > affecting src:pam?
Apparmor was fixed in 4.1.0-1 the problem is the upgrade path bookworm to trixe. pam need to be upgraded after apparmor and moreover in order to be in the safe side I think we must release a 3 version (bookworm) including this profiles rouca > > Regards, > Salvatore
signature.asc
Description: This is a digitally signed message part.

