Insecure Default Initialization of Resource Affecting pam-himmelblau package, versions <0.9.23+git.0.9776141-160000.1.1


Severity

Recommended
0.0
high
0
10

Based on SUSE Linux Enterprise Server security rating.

Threat Intelligence

EPSS
0.14% (4th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-SLES1600-PAMHIMMELBLAU-14375844
  • published11 Dec 2025
  • disclosed27 Nov 2025

Introduced: 27 Nov 2025

CVE-2025-59044  (opens in a new tab)
CWE-1188  (opens in a new tab)

How to fix?

Upgrade SLES:16.0.0 pam-himmelblau to version 0.9.23+git.0.9776141-160000.1.1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream pam-himmelblau package and not the pam-himmelblau package as distributed by SLES. See How to fix? for SLES:16.0.0 relevant fixed versions and status.

Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. Himmelblau 0.9.x derives numeric GIDs for Entra ID groups from the group display name when himmelblau.conf id_attr_map = name (the default configuration). Because Microsoft Entra ID allows multiple groups with the same displayName (including end-user–created personal/O365 groups, depending on tenant policy), distinct directory groups can collapse to the same numeric GID on Linux. This issue only applies to Himmelblau versions 0.9.0 through 0.9.22. Any resource or service on a Himmelblau-joined host that enforces authorization by numeric GID (files/dirs, etc.) can be unintentionally accessible to a user who creates or joins a different Entra/O365 group that happens to share the same displayName as a privileged security group. Users should upgrade to 0.9.23, or 1.0.0 or later, to receive a patch. Group to GID mapping now uses Entra ID object IDs (GUIDs) and does not collide on same-name groups. As a workaround, use tenant policy hardening to restrict arbitrary group creation until all hosts are patched.

CVSS Base Scores

version 3.1