CVE-2025-5689: Improper Permission Management in SSH Session Handling

Published Jun 16, 2025
·
Updated

Impact When an authd user logs in via SSH for the first time (meaning they do not yet exist in the authd user database) and successfully authenticates via the configured broker, the user is considered a member of the root group in the context of that SSH session. This situation may allow the user to read and write files that are accessible by the root group, to which they should not have access. The user does not get root privileges or any capabilities beyond the access granted to the root group.

Preconditions under which this vulnerability affects a system authd was installed via the PPA. An OAuth 2.0 application was registered in Microsoft Entra ID or Google IAM, and the respective authd broker was installed (authd-msentraid or authd-google) and configured. sshd was configured to enable SSH access with authd, i.e.: UsePAM yes KbdInteractiveAuthentication yes The username is allowed by the sshallowedsuffixes option in the broker configuriation. The user is allowed by the allowedusers option in the broker configuration. The user successfully authenticates via the authd broker (Entra ID or Google IAM). The user did not log in locally before.

Patches Fixed by https://github.com/ubuntu/authd/commit/619ce8e55953b970f1765ddaad565081538151ab

Workarounds Configure the SSH server to not allow authenticating via authd, for example by setting UsePAM no or KbdInteractiveAuthentication no in the sshdconfig (see https://documentation.ubuntu.com/authd/stable/howto/login-ssh/#ssh-configuration).

Other sources

A flaw was found in the temporary user record that authd uses in the pre-auth NSS. As a result, a user login for the first time will be considered to be part of the root group in the context of that SSH session.

MITRE

Affected Software

2 affected componentsFixes available
go/github.com/ubuntu/authd<0.5.4
0.5.4
Canonical Authd<0.5.4

Event History

Jun 16, 2025
CVE Published
via MITRE·11:37 AM
Data Sourced
via MITRE·11:37 AM
DescriptionSeverity
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
RemedyAffected Software
Advisory Published
via GitHub·04:01 PM
Data Sourced
via GitHub·04:01 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-5689?

CVE-2025-5689 is considered a critical vulnerability due to its impact on user authentication and unauthorized access to root privileges.

2

How do I fix CVE-2025-5689?

To fix CVE-2025-5689, upgrade the authd package to version 0.5.4 or later.

3

What is the impact of CVE-2025-5689?

The impact of CVE-2025-5689 is that unauthenticated users logging in via SSH can gain root group membership inappropriately, potentially leading to privilege escalation.

4

Which software is affected by CVE-2025-5689?

CVE-2025-5689 affects versions of the authd package up to and including version 0.5.4.

5

Who is responsible for addressing CVE-2025-5689?

It is the responsibility of system administrators using affected versions of authd to address CVE-2025-5689 by applying the necessary patches or upgrades.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203