Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-48983— pam_usb: TOCTOU race condition in pad directory creation allows symlink substitution

Quick assessment

Affected
mcdope pam_usb
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

mcdope pam_usb是mcdope的认证模块。 McDope pam_usb 0.9.2之前版本存在竞争条件问题漏洞,该漏洞源于在设备和用户一次性密码目录创建过程中存在符号链接竞争条件,使用检查后执行模式,可能导致本地攻击者利用符号链接替换目标路径,将一次性密码文件写入攻击者控制的位置,从而泄露未来密码值或破坏身份验证。

CVSS 5.8 · Medium EPSS 0.11% · P1

Possible ATT&CK Techniques 1 AI

T1564.004 · NTFS File Attributes

Affected Version Matrix 1

VendorProduct Version RangeStatus
mcdope pam_usb < 0.9.2 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-48983

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
pam_usb: TOCTOU race condition in pad directory creation allows symlink substitution
Source: CVE Program / CVE List V5
Vulnerability Description
pam_usb provides hardware authentication for Linux using ordinary removable media. In versions prior to 0.9.2, a symlink race condition exists in per-device and per-user pad directory creation. pam_usb uses a check-then-act pattern: it calls lstat() to test for existence and then calls mkdir() separately to create the directory. A local attacker can win the race between these calls by replacing the target path with a symlink to a directory they control. If successful, one-time pad files may be written to an attacker-controlled location, potentially exposing future pad values before use or disrupting authentication. This issue has been fixed in version 0.9.2.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
检查时间与使用时间(TOCTOU)的竞争条件
Source: CVE Program / CVE List V5
Vulnerability Title
McDope pam_usb 竞争条件问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
mcdope pam_usb是mcdope的认证模块。 McDope pam_usb 0.9.2之前版本存在竞争条件问题漏洞,该漏洞源于在设备和用户一次性密码目录创建过程中存在符号链接竞争条件,使用检查后执行模式,可能导致本地攻击者利用符号链接替换目标路径,将一次性密码文件写入攻击者控制的位置,从而泄露未来密码值或破坏身份验证。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
mcdope pam_usb < 0.9.2 -

II. Public POCs for CVE-2026-48983

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-48983

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-48983 (1)

Vendor Advisories for CVE-2026-48983 (1)

Same Patch Batch · mcdope · 2026-06-18 · 7 CVEs total

CVE-2026-48981 6.7 MEDIUM pam_usb: xmlReadFile flags=0 permits XXE network entity fetching in conf.c
CVE-2026-48980 6.3 MEDIUM pam_usb: getenv() used in PAM context allows environment variable injection into local-che
CVE-2026-48982 5.8 MEDIUM pam_usb: Missing O_EXCL on pad temp file creation allows concurrent update race
CVE-2026-48985 5.5 MEDIUM pam_usb: NULL Dereference Crash in pusb_is_loginctl_local when loginctl Returns Empty Remo
CVE-2026-48984 4.7 MEDIUM pam_usb: xfree() does not call explicit_bzero — sensitive cryptographic material may linge
CVE-2026-48986 4.7 MEDIUM pam_usb: Infinite loop DoS in process-tree walk when parent process exits during authentic

IV. Related Vulnerabilities

V. Comments for CVE-2026-48983

No comments yet


Leave a comment