pam-selinux

MEDIUM
maintainer IooNag 22 votes scanned 2026-10-05 23:40:58.404909
View on AUR
Why flagged

The package grants elevated privileges or installs an update path outside pacman: a /etc/sudoers.d rule (often passwordless), a setuid/setgid binary, or a self-update script/service that can fetch and run future code with no checksum verification. The initial install may be verified, but the ongoing privilege + update surface is a real supply-chain / privilege-escalation risk.

Triggered rules

Medium Privileged / out-of-pacman install (sudoers, setuid, or self-update) privileged_install

The package grants elevated privileges or installs an update path outside pacman: a /etc/sudoers.d rule (often passwordless), a setuid/setgid binary, or a self-update script/service that can fetch and run future code with no checksum verification. The initial install may be verified, but the ongoing privilege + update surface is a real supply-chain / privilege-escalation risk.

  • PKGBUILD:103 chmod +s "${pkgdir}"/usr/bin/unix_chkpwd

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Tobias Powalowski <tpowa@archlinux.org>
2# Maintainer: Levente Polyak <anthraxx[at]archlinux[dot]org>
3# Contributor: judd <jvinet@zeroflux.org>
4# SELinux Maintainer: Nicolas Iooss (nicolas <dot> iooss <at> m4x <dot> org)
5# SELinux Contributor: Timothée Ravier <tim@siosm.fr>
6# SELinux Contributor: Nicky726 <nicky726@gmail.com>
7#
8# This PKGBUILD is maintained on https://github.com/archlinuxhardened/selinux.
9# If you want to help keep it up to date, please open a Pull Request there.
10
11pkgname=pam-selinux
12pkgver=1.7.3
13pkgrel=1
14pkgdesc="SELinux aware PAM (Pluggable Authentication Modules) library"
15arch=('x86_64' 'aarch64')
16license=('GPL-2.0-only')
17url="http://linux-pam.org"
18depends=(
19 audit
20 glibc
21 libaudit.so
22 libcrypt.so
23 libnsl
24 libselinux
25 libtirpc
26 libxcrypt
27 pambase-selinux
28 systemd-libs
29)
30makedepends=(
31 docbook-xml
32 docbook-xsl
33 docbook5-xml
34 flex
35 fop
36 git
37 libxslt
38 meson
39 w3m
40)
41conflicts=("${pkgname/-selinux}" "selinux-${pkgname/-selinux}")
42provides=(
43 libpam.so
44 libpamc.so
45 libpam_misc.so
46 "${pkgname/-selinux}=${pkgver}-${pkgrel}"
47 "selinux-${pkgname/-selinux}=${pkgver}-${pkgrel}"
48)
49backup=(
50 etc/security/{access.conf,faillock.conf,group.conf,limits.conf,namespace.conf,namespace.init,pwhistory.conf,pam_env.conf,time.conf}
51 etc/environment
52)
53groups=('selinux')
54source=("pam::git+https://github.com/linux-pam/linux-pam?signed#tag=v${pkgver}"
55 "${pkgname/-selinux}.tmpfiles")
56validpgpkeys=(
57 '8C6BFD92EE0F42EDF91A6A736D1A7F052E5924BB' # Thorsten Kukuk
58 '296D6F29A020808E8717A8842DB5BD89A340AEB7' # Dimitry V. Levin <ldv@altlinux.org>
59 '7BECFE3AF7B280BB52FF77F104BA4521C996DDE1' # Dmitry V. Levin <ldv@strace.io
60)
61b2sums=('a533679b3362f9ebb67a7652454af9402ee845e1bd6f99064b870b38f9dc7a6ec62a73d65af2086e863448742714b6eb6a91d0ad2209e77325fd127635230648'
62 '36582c80020008c3810b311a2e126d2fb4ffc94e565ea4c0c0ab567fdb92943e269781ffa548550742feb685847c26c340906c7454dcc31df4e1e47d511d8d6f')
63options=('!emptydirs')
64
65prepare() {
66 cd "${pkgname/-selinux}"
67 # apply patch from the source array (should be a pacman feature)
68 local src
69 for src in "${source[@]}"; do
70 src="${src%%::*}"
71 src="${src##*/}"
72 [[ $src = *.patch ]] || continue
73 echo "Applying patch ${src}..."
74 patch -Np1 < "../${src}"
75 done
76}
77
78build() {
79 arch-meson "${pkgname/-selinux}" \
80 -Dlogind=enabled \
81 -Deconf=disabled \
82 -Dselinux=enabled \
83 -Delogind=disabled \
84 -Dpam_userdb=disabled \
85 -Dpwaccess=disabled \
86 -Dvendordir='' \
87 build
88 meson compile -C build
89}
90
91check() {
92 meson test -C build
93}
94
95package() {
96 meson install -C build --destdir "${pkgdir}"
97 install -Dm 644 ${pkgname/-selinux}.tmpfiles "${pkgdir}"/usr/lib/tmpfiles.d/${pkgname/-selinux}.conf
98
99 # remove unreproducible pdf files
100 rm "${pkgdir}"/usr/share/doc/Linux-PAM/*.pdf
101
102 # set unix_chkpwd uid
103 chmod +s "${pkgdir}"/usr/bin/unix_chkpwd
104}
105
106

Changes since previous scan

--- PKGBUILD @ 2026-06-18 16:11
+++ PKGBUILD @ 2026-10-05 23:40
@@ -9,8 +9,8 @@
# If you want to help keep it up to date, please open a Pull Request there.
pkgname=pam-selinux
-pkgver=1.7.2
-pkgrel=2
+pkgver=1.7.3
+pkgrel=1
pkgdesc="SELinux aware PAM (Pluggable Authentication Modules) library"
arch=('x86_64' 'aarch64')
license=('GPL-2.0-only')
@@ -58,7 +58,7 @@
'296D6F29A020808E8717A8842DB5BD89A340AEB7' # Dimitry V. Levin <ldv@altlinux.org>
'7BECFE3AF7B280BB52FF77F104BA4521C996DDE1' # Dmitry V. Levin <ldv@strace.io
)
-b2sums=('7fac16161ee8abab8639f5661badcf29536f0df71fec085075b657f91264fa7e616ae74c60e77fd8503d767517847dda877f583f20ca354e2ba45a381d89c998'
+b2sums=('a533679b3362f9ebb67a7652454af9402ee845e1bd6f99064b870b38f9dc7a6ec62a73d65af2086e863448742714b6eb6a91d0ad2209e77325fd127635230648'
'36582c80020008c3810b311a2e126d2fb4ffc94e565ea4c0c0ab567fdb92943e269781ffa548550742feb685847c26c340906c7454dcc31df4e1e47d511d8d6f')
options=('!emptydirs')

Scan history

Scanned at (UTC)SeverityRules
2026-10-05 23:40:58 Medium 1
2026-06-18 16:11:54 Clean 0

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion