CVE-2018-9275: Yubico Pam

High severity, CVSS 8.2. EPSS: 1.4% chance of exploitation in the next 30 days.

In check_user_token in util.c in the Yubico PAM module (aka pam_yubico) 2.18 through 2.25, successful logins can leak file descriptors to the auth mapping file, which can lead to information disclosure (serial number of a device) and/or DoS (reaching the maximum number of file descriptors).

Affected products

  • Yubico Yubico Pam: from 2.18, up to and including 2.25

Published 2018-04-04. Last modified 2026-06-17.