Vulnerability in pam-u2f allowing bypass of hardware token authentication

The openSUSE project developers have discovered a vulnerability (CVE-2025-23013) in the PAM module pam-u2f, used for authentication through YubiKey tokens, Yubico Security Key, YubiHSM, and other FIDO devices supporting the U2F (Universal 2nd Factor) protocol. The vulnerability allows a user with unprivileged local access to the system, under certain PAM configurations, to authenticate without inserting a hardware token. In practice, the pam-u2f module is typically connected for two-factor or passwordless authentication using tokens (for example, to confirm permissions for executing commands via the su and sudo utilities).

The vulnerability is caused by the pam_sm_authenticate() function incorrectly returning the value PAM_IGNORE. This value is returned in the case of an error during the execution of gethostname(), pam_modutil_drop_priv(), pam_modutil_regain_priv(), or resolve_authfile_path(), as well as during memory allocation issues in strdup() or calloc(). The problem is that the libpam library, upon receiving a result code of PAM_IGNORE from the PAM module, will return the final code PAM_SUCCESS, indicating a successful authentication, if some other PAM module in the chain has returned a successful authentication result.

When using the pam-u2f module in conjunction with pam_unix for two-factor authentication, the vulnerability allows successful authentication in the case of a successful password check without confirming the second factor. When performing passwordless authentication via the hardware token, pam-u2f may be used in conjunction with the PAM module pam_faillock, which limits the number of authentication attempts and returns PAM_SUCCESS if the limit has not been reached.

As an example of an attack, bypassing token verification when executing privileged commands as a local user, using the sudo and su utilities, is cited. During the execution of these commands, an attacker may create conditions for the pam-u2f module to return the value PAM_IGNORE, for example, by exhausting available memory. The issue has been fixed in version pam-u2f 1.3.1.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster