Bug#1139212: openssh-server: pam_lastlog2(sshd:session): SQL error: database is locked

Francesco Potortì <[email protected]> Sun, 07 Jun 2026 11:49:54 +0200
Newsgroups gmane.linux.debian.devel.ssh
Organization ISTI-CNR, via Moruzzi 1, www.isti.cnr.it
Message-ID <[email protected]>
Package: openssh-server
Version: 1:10.3p1-1
Severity: minor
File: /usr/lib/openssh/sshd-session

From=20time to time I see these two line in the auth.log:

pam_lastlog2(sshd:session): Failed to execute statement: database is locked
pam_lastlog2(sshd:session): SQL error: database is locked

These are part of a legitimate user's auth sequence which fails.  The user =
name is USER


sshd-session[1701679]: Accepted publickey for USER from 109.234.58.120 port=
 64709 ssh2: RSA SHA256:qVocyzOxy2cJBE0tcTZ3vxqJWmbjG7oNN5fOBX+Wp7M
sshd-session[1701679]: pam_unix(sshd:session): session opened for user USER=
(uid=3D1000) by USER(uid=3D0)
systemd-logind[1752]: New session '410904' of user 'USER' with class 'user'=
 and type 'tty'.
sshd-session[1701691]: Accepted publickey for USER from 109.234.58.120 port=
 60272 ssh2: RSA SHA256:qVocyzOxy2cJBE0tcTZ3vxqJWmbjG7oNN5fOBX+Wp7M
sshd-session[1701691]: pam_unix(sshd:session): session opened for user USER=
(uid=3D1000) by USER(uid=3D0)
systemd-logind[1752]: New session '410905' of user 'USER' with class 'user'=
 and type 'tty'.
sshd-session[1701691]: pam_lastlog2(sshd:session): Failed to execute statem=
ent: database is locked
sshd-session[1701691]: pam_lastlog2(sshd:session): SQL error: database is l=
ocked
sshd-session[1701703]: Received disconnect from 109.234.58.120 port 60272:1=
1: disconnected by user
sshd-session[1701703]: Disconnected from user USER 109.234.58.120 port 60272
sshd-session[1701691]: pam_unix(sshd:session): session closed for user USER
systemd-logind[1752]: Session 410905 logged out. Waiting for processes to e=
xit.
systemd-logind[1752]: Removed session 410905.




=2D- System Information:
Debian Release: forky/sid
  APT prefers testing
  APT policy: (990, 'testing'), (500, 'stable-security'), (500, 'unstable')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 6.19.6+deb14-amd64 (SMP w/24 CPU threads; PREEMPT)
Kernel taint flags: TAINT_PROPRIETARY_MODULE, TAINT_OOT_MODULE, TAINT_UNSIG=
NED_MODULE
Locale: LANG=3DC.UTF-8, LC_CTYPE=3Dit_IT.UTF-8 (charmap=3DUTF-8), LANGUAGE =
not set
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

Versions of packages openssh-server depends on:
ii  debconf [debconf-2.0]       1.5.92
ii  libaudit1                   1:4.1.2-1+b1
ii  libc6                       2.42-16
ii  libcom-err2                 1.47.4-1
ii  libgssapi-krb5-2            1.22.1-2+b1
ii  libkrb5-3                   1.22.1-2+b1
ii  libpam-modules              1.7.0-5+b2
ii  libpam-runtime              1.7.0-5
ii  libpam0g                    1.7.0-5+b2
ii  libselinux1                 3.10-1
ii  libssl3t64                  3.6.2-1
ii  libwrap0                    7.6.q-37
ii  libwtmpdb0                  0.75.0-5+b1
ii  openssh-client              1:10.3p1-1
ii  openssh-sftp-server         1:10.3p1-1
ii  procps                      2:4.0.4-9+b2
ii  runit-helper                2.16.6
ii  systemd [systemd-sysusers]  260.1-1
ii  ucf                         3.0053
ii  zlib1g                      1:1.3.dfsg+really1.3.2-3

Versions of packages openssh-server recommends:
ii  libpam-systemd [logind]  260.1-1
ii  ncurses-term             6.6+20251231-1
ii  passwd                   1:4.19.3-2
ii  xauth                    1:1.1.2-1.1

Versions of packages openssh-server suggests:
pn  molly-guard                      <none>
pn  monkeysphere                     <none>
ii  ssh-askpass-gnome [ssh-askpass]  1:10.3p1-1
pn  ufw                              <none>

=2D- debconf information:
  ssh/vulnerable_host_keys:
  ssh/encrypted_host_key_but_no_keygen:
  openssh-server/password-authentication: true
* ssh/use_old_init_script: true
  ssh/disable_cr_auth: false
* openssh-server/permit-root-login: false