A flaw was found in the temporary user record that authd uses in the pre-auth NSS. As a result, a user login for the first time will be considered to be part of the root group in the context of that SSH session.
{ "versions": [ { "introduced": "0" }, { "fixed": "0.5.4" } ] }
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-5689.json"