Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-5864-1 | pam-pkcs11 security update |
Ubuntu USN |
USN-7363-1 | PAM-PKCS#11 vulnerabilities |
Tue, 20 Jan 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | pam_pkcs11: authentication bypass in error situations | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Mon, 19 Jan 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Opensc Project
Opensc Project opensc Opensc Project pam Pkcs11 |
|
| Vendors & Products |
Opensc Project
Opensc Project opensc Opensc Project pam Pkcs11 |
Fri, 16 Jan 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 16 Jan 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 16 Jan 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In OpenSC pam_pkcs11 before 0.6.13, pam_sm_authenticate() wrongly returns PAM_IGNORE in many error situations (such as an error triggered by a smartcard before login), allowing authentication bypass. | |
| Weaknesses | CWE-393 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-01-16T18:07:08.192Z
Reserved: 2025-01-23T00:00:00.000Z
Link: CVE-2025-24531
Updated: 2026-01-16T18:07:08.192Z
Status : Deferred
Published: 2026-01-16T18:16:06.817
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-24531
OpenCVE Enrichment
Updated: 2026-01-19T09:20:56Z
Debian DSA
Ubuntu USN