In Yubico pam-u2f 1.0.7, when configured with debug and a custom debug log file is set using debug_file, that file descriptor is not closed when a new process is spawned. This leads to the file descriptor being inherited into the child process; the child process can then read from and write to it. This can leak sensitive information and also, if written to, be used to fill the disk or plant misinformation.
CVSS Details
- CVSS 3.1 Base Score: 8.1
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jun 4, 2019 |
| Debian | — | Upgrade pam-u2f | Jul 30, 2024 | Jun 4, 2019 |
| Suse | — | Upgrade libu2f-host-docUpgrade libu2f-host0Upgrade u2f-hostUpgrade libu2f-host-develUpgrade pam_u2f | Jul 5, 2019 | Jun 4, 2019 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Jun 4, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub