Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

pam_usb — Vulnerabilities & Security Advisories 22

All 22 CVE vulnerabilities found in pam_usb, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities associated with the PAM_USB product, specifically focusing on its implementation of USB-based two-factor authentication and the underlying cryptographic weaknesses within its hardware token ecosystem. The collection encompasses a broad range of reported flaws, including buffer overflows in the host-side driver software, authentication bypasses in the challenge-response protocol, and firmware update vulnerabilities that could allow persistent malicious code injection. These records span from the initial public release of the device through recent patches addressing critical security gaps identified over the past decade. Readers can utilize this index to track the vendor’s advisory history, understand the specific technical characteristics of weaknesses common to USB peripheral authentication devices, and review the complete vulnerability lifecycle for this particular hardware class. By examining these entries, security professionals can identify patterns in how the product handles input validation and key storage, assess the risk profile of deploying similar USB tokens in their own infrastructure, and verify whether specific legacy versions remain exposed to known exploits. The data serves as a technical reference for incident responders and auditors who need to correlate specific error messages or behavioral anomalies with documented security defects, providing a structured view of the product’s historical security posture without requiring access to fragmented vendor support channels.

Vendor: mcdope

CVE ID Title CVSS Severity Published
CVE-2026-48980 pam_usb: getenv() used in PAM context allows environment variable injection into local-check logic CWE-454 6.3 Medium 2026-06-18
CVE-2026-48983 pam_usb: TOCTOU race condition in pad directory creation allows symlink substitution CWE-367 5.8 Medium 2026-06-18
CVE-2026-48982 pam_usb: Missing O_EXCL on pad temp file creation allows concurrent update race CWE-362 5.8 Medium 2026-06-18
CVE-2026-48981 pam_usb: xmlReadFile flags=0 permits XXE network entity fetching in conf.c CWE-611 6.7 Medium 2026-06-18
CVE-2026-48985 pam_usb: NULL Dereference Crash in pusb_is_loginctl_local when loginctl Returns Empty Remote Field CWE-476 5.5 Medium 2026-06-18
CVE-2026-48986 pam_usb: Infinite loop DoS in process-tree walk when parent process exits during authentication CWE-835 4.7 Medium 2026-06-18
CVE-2026-48984 pam_usb: xfree() does not call explicit_bzero — sensitive cryptographic material may linger in freed heap CWE-14 4.7 Medium 2026-06-18
CVE-2026-44712 pam_usb: Shell injection via device UUID and username in pamusb-conf and pamusb-agent CWE-78 8.2 High 2026-05-27
CVE-2026-44709 pam_usb: PINENTRY_FALLBACK_APP environment variable allows arbitrary command execution CWE-78 7.8 High 2026-05-27
CVE-2026-44710 pam_usb: NULL pointer dereference from UDisks device fields causes PAM crash and login denial-of-service CWE-476 4.6 Medium 2026-05-27
CVE-2026-44711 pam_usb: Symlink attacks on pad directory and pad files enable authentication bypass and root file corruption CWE-59 7.9 High 2026-05-27
CVE-2026-44713 pam_usb: Command injection via $TMUX environment variable leads to RCE as root CWE-78 8.8 High 2026-05-27
CVE-2026-47269 pam_usb: deny_remote feature incorrectly classifies IPv4-mapped IPv6 remote connections as local CWE-284 7.4 High 2026-05-27
CVE-2026-47270 pam_usb: strtok() race condition in multi-threaded PAM hosts can corrupt deny_remote result CWE-362 6.3 Medium 2026-05-27
CVE-2026-47271 pam_usb: OOM guards removed by -DNDEBUG cause NULL dereference and authentication process crash CWE-476 5.1 Medium 2026-05-27
CVE-2026-47272 pam_usb: OTP pad authentication bypass via missing system pad check and uninitialized RNG buffer CWE-287 7.1 High 2026-05-27
CVE-2026-47273 pam_usb: XPath injection via PAM-supplied identifiers in pam_usb configuration queries CWE-91 6.5 Medium 2026-05-27
CVE-2026-47274 pam_usb: Uncontrolled search path in pam_usb tools allows privilege escalation via PATH manipulation CWE-427 6.3 Medium 2026-05-27
CVE-2026-48064 pam_usb: PAM_RHOST check skipped when deny_remote=false allows XDMCP authentication bypass CWE-863 8.1 High 2026-05-27
CVE-2026-48065 pam_usb: Unchecked integer multiplication before xmalloc() in conf.c allows heap-based buffer overflow on 32-bit targets CWE-122 6.7 Medium 2026-05-27
CVE-2026-48066 pam_usb: Thread-unsafe static pointer in log.c causes data race under concurrent PAM authentication CWE-362 5.7 Medium 2026-05-27
CVE-2026-48792 pam_usb: pusb_has_virtual_input_device() silently discards EACCES, disabling remote desktop detection under non-root execution CWE-390 4.4 Medium 2026-05-27

All 22 known CVE vulnerabilities affecting pam_usb with full Chinese analysis, references, and POCs where available.