In OpenSC pampkcs11 before 0.6.13, pamsmauthenticate() wrongly returns PAMIGNORE in many error situations (such as an error triggered by a smartcard before login), allowing authentication bypass.
[ { "events": [ { "introduced": "pam_pkcs11" }, { "fixed": "0.6.13" } ] } ]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-24531.json"