A flaw was found in the temporary user record that authd uses in the pre-auth NSS. As a result, a user login for the first time will be considered to be part of the root group in the context of that SSH session.
References
| Link | Resource |
|---|---|
| https://github.com/ubuntu/authd/security/advisories/GHSA-g8qw-mgjx-rwjr | Patch Vendor Advisory |
Configurations
History
No history.
Information
Published : 2025-06-16 12:15
Updated : 2025-08-26 16:04
NVD link : CVE-2025-5689
Mitre link : CVE-2025-5689
CVE.ORG link : CVE-2025-5689
JSON object : View
Products Affected
canonical
- authd
CWE
CWE-269
Improper Privilege Management
