[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#1037122: libpam-ssh-agent-auth: Sudo with ECDSA key segfaults



Package: libpam-ssh-agent-auth
Version: 0.10.3-3+b1
Severity: normal
X-Debbugs-Cc: mfite@sabarca.cat

Dear Maintainer,

*** Reporter, please consider answering these questions, where appropriate ***

   * What led up to the situation?

   	Login with ssh -A and trying to sudo with a yubikey:

	
	Jun  5 12:09:39 vls15775 sudo[3083994]: pam_ssh_agent_auth: secure_filename: terminating check at '/home/mfite'
	Jun  5 12:09:39 vls15775 sudo[3083994]: pam_ssh_agent_auth: matching key found: file/command /home/mfite/.ssh/authorized_keys, line 1
	Jun  5 12:09:39 vls15775 sudo[3083994]: pam_ssh_agent_auth: Found matching ECDSA key: f5:4f:d7:06:73:d4:e9:be:72:60:54:e4:fe:59:70:0e


   * What exactly did you do (or not do) that was effective (or
     ineffective)?

	sudo su -	

	# cat /etc/pam.d/sudo
	#%PAM-1.0
	auth	sufficient	pam_ssh_agent_auth.so file=~/.ssh/authorized_keys debug

	@include common-auth
	@include common-account
	@include common-session-noninteractive

   * What was the outcome of this action?


   	Segfault of sudo:

	[16590023.461986] sudo[3083994]: segfault at 8 ip 00007f6a8ae4f770 sp 00007ffc3696af78 error 4 in libcrypto.so.1.1[7f6a8ae04000+1a7000]

   * What outcome did you expect instead?


   	Sudo su - without segfault

*** End of the template - remove these template lines ***


-- System Information:
Debian Release: 11.7
  APT prefers stable-updates
  APT policy: (500, 'stable-updates'), (500, 'stable-security'), (500, 'proposed-updates'), (500, 'stable')
Architecture: amd64 (x86_64)

Kernel: Linux 5.10.0-19-amd64 (SMP w/2 CPU threads)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), LANGUAGE not set
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

Versions of packages libpam-ssh-agent-auth depends on:
ii  libc6      2.31-13+deb11u6
ii  libpam0g   1.4.0-9+deb11u1
ii  libssl1.1  1.1.1n-0+deb11u5

libpam-ssh-agent-auth recommends no packages.

libpam-ssh-agent-auth suggests no packages.

-- no debconf information


Reply to: