Ubuntu Security Update USN-7363-1: PAM-PKCS#11 vulnerabilities

LinuxBot

Member
Joined
Apr 25, 2017
Messages
5,833
Reaction score
74
Credits
-1,257
Marcus Rückert and Matthias Gerstner discovered that PAM-PKCS#11 did not properly handle certain return codes when authentication was not possible. An attacker could possibly use this issue to bypass authentication. This issue only affected Ubuntu 24.04 LTS and Ubuntu 24.10. (CVE-2025-24531) It was discovered that PAM-PKCS#11 did not require a private key signature for authentication by default. An attacker could possibly use this issue to bypass authentication. (CVE-2025-24032)

Continue reading...
 


Follow Linux.org

Members online


Top