CVE-2025-5689

A flaw was found in the temporary user record that authd uses in the pre-auth NSS. As a result, a user login for the first time will be considered to be part of the root group in the context of that SSH session.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:canonical:authd:*:*:*:*:*:*:*:*

History

26 Aug 2025, 16:04

Type Values Removed Values Added
References () https://github.com/ubuntu/authd/security/advisories/GHSA-g8qw-mgjx-rwjr - () https://github.com/ubuntu/authd/security/advisories/GHSA-g8qw-mgjx-rwjr - Patch, Vendor Advisory
CPE cpe:2.3:a:canonical:authd:*:*:*:*:*:*:*:*
First Time Canonical
Canonical authd

17 Jun 2025, 18:15

Type Values Removed Values Added
CWE CWE-269

17 Jun 2025, 15:15

Type Values Removed Values Added
Summary
  • (es) Se detectó una falla en el registro de usuario temporal que authd utiliza en el NSS previo a la autorización. Como resultado, un usuario que inicia sesión por primera vez se considerará parte del grupo root en el contexto de esa sesión SSH.
CVSS v2 : unknown
v3 : 6.4
v2 : unknown
v3 : 8.5

16 Jun 2025, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-16 12:15

Updated : 2025-08-26 16:04


NVD link : CVE-2025-5689

Mitre link : CVE-2025-5689

CVE.ORG link : CVE-2025-5689


JSON object : View

Products Affected

canonical

  • authd
CWE
CWE-269

Improper Privilege Management