Package: libpam0g Version: 1.7.0-2 Severity: critical Upstream removed the check for the sys/fsuid.h header, which means HAVE_SYS_FSUID_H is never defined anymore. The debian hurd_no_setfsuid patch now always uses the fallback code, and pam_modutil_regain_priv now fails with a:
pam_modutil_regain_priv: setgroups failed: Operation not permitted error when using sudo and pam_u2f.so.