https://seclists.org/oss-sec/2025/q1/113: pam_pkcs11: Possible Authentication Bypass in Error Situations (CVE-2025-24531)
Published Feb 6, 2025
·Updated
Affected Software
1 affected component
Linux-PAM pam_pkcs11>=0.6.12
Frequently Asked Questions
1
What is the severity of CVE-2025-24531?
CVE-2025-24531 is considered a high severity vulnerability due to its potential for authentication bypass.
2
How do I fix CVE-2025-24531?
To fix CVE-2025-24531, upgrade to pam_pkcs11 version 0.6.13 or later, which addresses the authentication bypass issue.
3
What systems are affected by CVE-2025-24531?
CVE-2025-24531 affects any PAM stack that uses pam_pkcs11 version 0.6.12 as the sole authentication factor.
4
What is pam_pkcs11 in relation to CVE-2025-24531?
pam_pkcs11 is a module for Linux-PAM that enables PKCS#11 support for authentication, which is compromised in CVE-2025-24531.
5
When was CVE-2025-24531 published?
CVE-2025-24531 was published on February 6, 2025.