Executive brief
pam_usb is a tool that allows users to log into Linux systems using USB drives or other removable media instead of just passwords. A security flaw in its PIN entry component allows a local attacker to run unauthorized commands or scripts with elevated system privileges. Additionally, a separate issue could allow other users on the same computer to briefly see sensitive keyring passwords during the login process.
Technical details
A command injection vulnerability exists in the pamusb-pinentry component of pam_usb due to the insecure handling of the PINENTRY_FALLBACK_APP environment variable. The application retrieves this variable and passes it directly to subprocess.run() without validation, allowing a local attacker who can influence the process environment to execute arbitrary binaries with the privileges of the pam_usb toolchain. Additionally, the pamusb-keyring-unlock-gnome component was found to interpolate GNOME Keyring passwords into shell command strings, making them visible in the process list (/proc/<pid>/cmdline). These issues are addressed in version 0.8.7 by implementing strict path validation for the fallback application and passing passwords via stdin.
Affected products
- mcdope pam_usb < 0.8.7
Timeline
- 2026-05-07: advisory: Original GitHub advisory published
- 2026-05-27: disclosed: NVD publication date