PT-2025-27005 · Unknown · Himmelblau

Mulder

·

Published

2025-06-26

·

Updated

2026-04-15

·

CVE-2025-53013

CVSS v3.1

5.2

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions: Himmelblau versions 0.9.10 through 0.9.16
Description: A vulnerability in Himmelblau allows a user to authenticate to a Linux host using an invalid Linux Hello PIN when the host is offline. This issue arises from an incorrect assumption in the acquire token by hello for business key function, which fails to return a TPMFail error for an invalid Hello key when offline. Instead, the system transitions to an offline success state without validating the Hello key unlock. This impacts systems using Himmelblau for authentication with Hello PIN authentication enabled when operating in an offline state.
Recommendations: For Himmelblau versions 0.9.10 through 0.9.16, update to version 0.9.17 to resolve the issue. As a temporary workaround for users who cannot immediately upgrade, disable Hello PIN authentication by setting enable hello = false in /etc/himmelblau/himmelblau.conf to mitigate the vulnerability.

Exploit

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2025-53013
GHSA-J93J-PWM6-P97J
OPENSUSE-SU-2025:15229-1
SUSE-SU-2026:1361-1

Affected Products

Himmelblau