Yubico libu2f-host 1.1.6 contains unchecked buffers in devs.c, which could enable a malicious token to exploit a buffer overflow. An attacker could use this to attempt to execute malicious code using a crafted USB device masquerading as a security token on a computer where the affected library is currently in use. It is not possible to perform this attack with a genuine YubiKey.
CVSS Details
- CVSS 3.1 Base Score: 6.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Mar 17, 2019 |
| Debian | — | Upgrade libu2f-host | Feb 12, 2019 | Feb 11, 2019 |
| Gentoo Linux | — | Upgrade app-crypt/libu2f-host. | May 1, 2020 | Mar 21, 2019 |
| Suse | — | Upgrade libu2f-host0Upgrade libu2f-host-docUpgrade u2f-hostUpgrade libu2f-host-develUpgrade pam_u2f | Feb 19, 2019 | Feb 11, 2019 |
| Ubuntu | — | Upgrade libu2f-host | Nov 19, 2024 | Mar 21, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub