https://seclists.org/oss-sec/2025/q1/25: pam-u2f: problematic PAM_IGNOturn values in pam_sm_authenticate() (CVE-2025-23013)
Published Jan 16, 2025
·Updated
Affected Software
2 affected components
Linux-PAM libpam
Linux-PAM pam-u2f
Frequently Asked Questions
1
What is the severity of CVE-2025-23013?
CVE-2025-23013 has been classified with a severity level that indicates it poses potential risks to authentication mechanisms.
2
How do I fix CVE-2025-23013?
To fix CVE-2025-23013, ensure that you update the pam-u2f module to the latest version where the vulnerability has been addressed.
3
What systems are affected by CVE-2025-23013?
CVE-2025-23013 affects systems utilizing the pam-u2f module within the Linux-PAM framework.
4
What are the implications of CVE-2025-23013?
The implications of CVE-2025-23013 involve potential bypass of authentication mechanisms through problematic PAM_IGNOturn values.
5
Who should be concerned about CVE-2025-23013?
Administrators managing Linux systems with pam-u2f should be particularly concerned about CVE-2025-23013.