https://seclists.org/oss-sec/2025/q1/109: pam_pkcs11: Possible Authentication Bypass in Error Situations (CVE-2025-24531)
Published Feb 6, 2025
·Updated
Affected Software
1 affected component
Linux-PAM pam_pkcs11
Frequently Asked Questions
1
What is the severity of CVE-2025-24531?
CVE-2025-24531 is classified as a medium severity vulnerability that could lead to authentication bypass.
2
How do I fix CVE-2025-24531?
To fix CVE-2025-24531, update the pam_pkcs11 package to the latest version available from your distribution.
3
What systems are affected by CVE-2025-24531?
CVE-2025-24531 affects systems using the Linux-PAM pam_pkcs11 module for authentication.
4
What kind of attacks can exploit CVE-2025-24531?
CVE-2025-24531 can be exploited in scenarios leading to unauthorized access when certain error conditions arise.
5
Is there a workaround for CVE-2025-24531 if an update cannot be applied?
Currently, there are no documented workarounds for CVE-2025-24531 other than applying the appropriate software update.