CVE-2025-24031 - CVE House
Back to Database
Status published Medium CVE-2025-24031

PAM-PKCS#11 vulnerable to segmentation fault on ctrl-c/ctrl-d when asked for PIN

Vulnerability Description

PAM-PKCS#11 is a Linux-PAM login module that allows a X.509 certificate based user login. In versions 0.6.12 and prior, the pam_pkcs11 module segfaults when a user presses ctrl-c/ctrl-d when they are asked for a PIN. When a user enters no PIN at all, `pam_get_pwd` will never initialize the password buffer pointer and as such `cleanse` will try to dereference an uninitialized pointer. On my system this pointer happens to have the value 3 most of the time when running sudo and as such it will segfault. The most likely impact to a system affected by this issue is an availability impact due to a daemon that uses PAM crashing. As of time of publication, a patch for the issue is unavailable.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-24031

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

pam_pkcs11
Vulnerable Versions:
<= 0.6.12

Timeline

Official Publish: February 10th, 2025
Last Modified: February 10th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)