Security Advisory
CVE-2025-24531
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
In OpenSC pam_pkcs11 before 0.6.13, pam_sm_authenticate() wrongly returns PAM_IGNORE in many error situations (such as an error triggered by a smartcard before login), allowing authentication bypass.