Executive brief
pam_usb is a tool that allows users to log into Linux systems using a physical USB drive instead of a password. A flaw in how the software identifies these drives allows a specially crafted USB device to crash the login system. This can result in a denial-of-service where legitimate users are locked out of their computers or servers until the malicious device is removed.
Technical details
A NULL pointer dereference exists in src/device.c of pam_usb prior to version 0.8.7. The software passes the return values of udisks_drive_get_serial(), udisks_drive_get_vendor(), and udisks_drive_get_model() directly to strcmp() without verifying they are non-NULL. According to GIO/UDisks API documentation, these functions return NULL if a device does not expose those fields. An attacker with physical access can insert a USB device (or mass-storage gadget) lacking these descriptors to trigger a SIGSEGV in the PAM module. This crashes the authentication process, potentially locking out all users of the affected service. The issue is fixed in version 0.8.7 by adding explicit NULL checks.
Affected products
- mcdope pam_usb < 0.8.7
Timeline
- 2026-05-07: advisory: GitHub advisory published by maintainer
- 2026-05-27: disclosed: CVE published to NVD