Fedora 40: pam-u2f 2025-b58b563b77 Security Advisory Updates
Summary
The PAM U2F module provides an easy way to integrate the Yubikey (or
other U2F-compliant authenticators) into your existing user
authentication infrastructure.
Update Information:
pam-u2f 1.3.1 includes a fix to resolve CVE-2025-23013 (Partial Authentication Bypass). CVSS score 7.3. 1.3.2 is a fix for a regression that could impact existing use cases.
Change Log
* Thu Jan 16 2025 Gary Buhrmaster
References
[ 1 ] Bug #2338114 - CVE-2025-23013 pam-u2f: Partial Authentication Bypass in pam-u2f Software Package [fedora-40]
https://bugzilla.redhat.com/show_bug.cgi?id=2338114
Update Instructions
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-b58b563b77' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label