Pam Usb
Mcdope · 22 CVEs
pam_usb: getenv() used in PAM context allows environment variable injection into local-check logic
Jun 18, 2026
pam_usb: TOCTOU race condition in pad directory creation allows symlink substitution
Jun 18, 2026
pam_usb: Missing O_EXCL on pad temp file creation allows concurrent update race
Jun 18, 2026
pam_usb: xmlReadFile flags=0 permits XXE network entity fetching in conf.c
Jun 18, 2026
pam_usb: NULL Dereference Crash in pusb_is_loginctl_local when loginctl Returns Empty Remote Field
Jun 18, 2026
pam_usb: Infinite loop DoS in process-tree walk when parent process exits during authentication
Jun 18, 2026
pam_usb: xfree() does not call explicit_bzero — sensitive cryptographic material may linger in freed heap
Jun 18, 2026
pam_usb: Shell injection via device UUID and username in pamusb-conf and pamusb-agent
May 27, 2026
pam_usb: PINENTRY_FALLBACK_APP environment variable allows arbitrary command execution
May 27, 2026
pam_usb: NULL pointer dereference from UDisks device fields causes PAM crash and login denial-of-service
May 27, 2026
pam_usb: Symlink attacks on pad directory and pad files enable authentication bypass and root file corruption
May 27, 2026
pam_usb: Command injection via $TMUX environment variable leads to RCE as root
May 27, 2026
pam_usb: deny_remote feature incorrectly classifies IPv4-mapped IPv6 remote connections as local
May 27, 2026
pam_usb: strtok() race condition in multi-threaded PAM hosts can corrupt deny_remote result
May 27, 2026
pam_usb: OOM guards removed by -DNDEBUG cause NULL dereference and authentication process crash
May 27, 2026
pam_usb: OTP pad authentication bypass via missing system pad check and uninitialized RNG buffer
May 27, 2026
pam_usb: XPath injection via PAM-supplied identifiers in pam_usb configuration queries
May 27, 2026
pam_usb: Uncontrolled search path in pam_usb tools allows privilege escalation via PATH manipulation
May 27, 2026
pam_usb: PAM_RHOST check skipped when deny_remote=false allows XDMCP authentication bypass
May 27, 2026
pam_usb: Unchecked integer multiplication before xmalloc() in conf.c allows heap-based buffer overflow on 32-bit targets
May 27, 2026
pam_usb: Thread-unsafe static pointer in log.c causes data race under concurrent PAM authentication
May 27, 2026
pam_usb: pusb_has_virtual_input_device() silently discards EACCES, disabling remote desktop detection under non-root ex…
May 27, 2026
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-48980 | pam_usb: getenv() used in PAM context allows environment variable injection into local-check logic | MEDIUM | 0.18% | Jun 18, 2026 |
| CVE-2026-48983 | pam_usb: TOCTOU race condition in pad directory creation allows symlink substitution | MEDIUM | 0.11% | Jun 18, 2026 |
| CVE-2026-48982 | pam_usb: Missing O_EXCL on pad temp file creation allows concurrent update race | MEDIUM | 0.12% | Jun 18, 2026 |
| CVE-2026-48981 | pam_usb: xmlReadFile flags=0 permits XXE network entity fetching in conf.c | MEDIUM | 0.15% | Jun 18, 2026 |
| CVE-2026-48985 | pam_usb: NULL Dereference Crash in pusb_is_loginctl_local when loginctl Returns Empty Remote Field | MEDIUM | 0.16% | Jun 18, 2026 |
| CVE-2026-48986 | pam_usb: Infinite loop DoS in process-tree walk when parent process exits during authentication | MEDIUM | 0.14% | Jun 18, 2026 |
| CVE-2026-48984 | pam_usb: xfree() does not call explicit_bzero — sensitive cryptographic material may linger in freed heap | MEDIUM | 0.15% | Jun 18, 2026 |
| CVE-2026-44712 | pam_usb: Shell injection via device UUID and username in pamusb-conf and pamusb-agent | HIGH | 0.21% | May 27, 2026 |
| CVE-2026-44709 | pam_usb: PINENTRY_FALLBACK_APP environment variable allows arbitrary command execution | HIGH | 0.21% | May 27, 2026 |
| CVE-2026-44710 | pam_usb: NULL pointer dereference from UDisks device fields causes PAM crash and login denial-of-service | MEDIUM | 0.25% | May 27, 2026 |
| CVE-2026-44711 | pam_usb: Symlink attacks on pad directory and pad files enable authentication bypass and root file corruption | HIGH | 0.21% | May 27, 2026 |
| CVE-2026-44713 | pam_usb: Command injection via $TMUX environment variable leads to RCE as root | HIGH | 0.21% | May 27, 2026 |
| CVE-2026-47269 | pam_usb: deny_remote feature incorrectly classifies IPv4-mapped IPv6 remote connections as local | HIGH | 0.45% | May 27, 2026 |
| CVE-2026-47270 | pam_usb: strtok() race condition in multi-threaded PAM hosts can corrupt deny_remote result | MEDIUM | 0.13% | May 27, 2026 |
| CVE-2026-47271 | pam_usb: OOM guards removed by -DNDEBUG cause NULL dereference and authentication process crash | MEDIUM | 0.16% | May 27, 2026 |
| CVE-2026-47272 | pam_usb: OTP pad authentication bypass via missing system pad check and uninitialized RNG buffer | HIGH | 0.17% | May 27, 2026 |
| CVE-2026-47273 | pam_usb: XPath injection via PAM-supplied identifiers in pam_usb configuration queries | MEDIUM | 0.41% | May 27, 2026 |
| CVE-2026-47274 | pam_usb: Uncontrolled search path in pam_usb tools allows privilege escalation via PATH manipulation | MEDIUM | 0.18% | May 27, 2026 |
| CVE-2026-48064 | pam_usb: PAM_RHOST check skipped when deny_remote=false allows XDMCP authentication bypass | HIGH | 0.54% | May 27, 2026 |
| CVE-2026-48065 | pam_usb: Unchecked integer multiplication before xmalloc() in conf.c allows heap-based buffer overflow on 32-bit targets | MEDIUM | 0.21% | May 27, 2026 |
| CVE-2026-48066 | pam_usb: Thread-unsafe static pointer in log.c causes data race under concurrent PAM authentication | MEDIUM | 0.14% | May 27, 2026 |
| CVE-2026-48792 | pam_usb: pusb_has_virtual_input_device() silently discards EACCES, disabling remote desktop detection under non-root execution | MEDIUM | 0.18% | May 27, 2026 |
Showing 1 to 22 of 22 CVEs