CVE-2025-6018: pamenv: Change the default to not read the user .pamenvironment file (bsc#1243226).
CVE-2025-6020: pam_namespace: convert functions that may operate on a user-controlled path to operate on file descriptors instead of absolute path (bsc#1244509).