shield Security update for pam_u2f
SUSE-SLE-Micro-6.0-221


This update for pam_u2f fixes the following issues: - update to 1.3.2: * Relax authfile permission check to a warning instead of an error to prevent a breaking change locking existing users out of their systems. - update to 1.3.1: * CVE-2025-23013: Fixed problematic PAM_IGNORE return values in `pam_sm_authenticate()`(bsc#1233517). * Changed return value when nouserok is enabled and the user has no credentials, PAM_IGNORE is used instead of PAM_SUCCESS. * Hardened checks of authfile permissions. * Hardened checks for nouserok. * Improved debug messages. * Improved documentation.

  • Release Date
    Mar 4 2025
  • References
    Bugzilla: 1233517
    CVEs: CVE-2025-23013
  • Type
    security
  • Severity
    moderate

cloud_download Downloads

SUSE Linux Micro 6.0 s390x
  • Packages
    pam_u2f
    U2F authentication integration into PAM
    1.3.2-1.1 lock rpm
SUSE Linux Micro 6.0 aarch64
  • Packages
    pam_u2f
    U2F authentication integration into PAM
    1.3.2-1.1 lock rpm
SUSE Linux Micro 6.0 x86_64
  • Packages
    pam_u2f
    U2F authentication integration into PAM
    1.3.2-1.1 lock rpm