PT-2025-6041 · Unknown+6 · Pam Pkcs11+6

Frankmorgner

·

Published

2024-11-06

·

Updated

2025-07-23

·

CVE-2025-24032

CVSS v2.0

9.7

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:P
Name of the Vulnerable Software and Affected Versions pam pkcs11 versions 0.6.0 through 0.6.12
Description PAM-PKCS#11 is a Linux-PAM login module that allows a X.509 certificate based user login. If cert policy is set to none (the default value), then pam pkcs11 will only check if the user is capable of logging into the token. An attacker may create a different token with the user's public data (e.g. the user's certificate) and a PIN known to the attacker. If no signature with the private key is required, then the attacker may now login as user with that created token. Approximately 11% of new vulnerabilities are related to improper authentication, with this issue being one of them.
Recommendations For versions 0.6.0 through 0.6.12, as a workaround, in pam pkcs11.conf, set at least cert policy = signature;. This change will ensure that the private key's signature is checked, preventing potential unauthorized access.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-3627
ALT-PU-2025-8016
BDU:2025-01619
BDU:2025-09007
CVE-2025-24032
DLA-4058-1
DSA-5864-1
GHSA-8R8P-7MGP-VF56
OPENSUSE-SU-2025:14738-1
OPENSUSE-SU-2025_0689-1
SUSE-SU-2025:0688-1
SUSE-SU-2025:0689-1
SUSE-SU-2025:0712-1
SUSE-SU-2025:20199-1
USN-7363-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Red Os
Suse
Ubuntu
Pam Pkcs11