Fedora 41: FEDORA-2025-29900cbe83 Critical pam-u2f Authentication Issue
Summary
The PAM U2F module provides an easy way to integrate the Yubikey (or
other U2F-compliant authenticators) into your existing user
authentication infrastructure.
Update Information:
pam-u2f 1.3.1 includes a fix to resolve CVE-2025-23013 (Partial Authentication Bypass). CVSS score 7.3. 1.3.2 is a fix for a regression that could impact existing use cases.
Change Log
* Thu Jan 16 2025 Gary Buhrmaster
References
[ 1 ] Bug #2338115 - CVE-2025-23013 pam-u2f: Partial Authentication Bypass in pam-u2f Software Package [fedora-41]
https://bugzilla.redhat.com/show_bug.cgi?id=2338115
Update Instructions
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-29900cbe83' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label