Executive brief
pam_usb is a tool that allows users to log into Linux systems using a physical USB drive instead of a password. A security flaw in how it handles session information allows a local user to bypass the hardware requirement and execute commands with administrative (root) privileges. By setting a specially crafted environment variable, an attacker can trick the system into running malicious code during the login process, leading to a full system takeover.
Technical details
A command injection vulnerability exists in the tmux remote-detection component of pam_usb (src/tmux.c). The software reads the user-controlled $TMUX environment variable and interpolates the socket-path component into a shell command string passed to popen() without proper sanitization. Because the variable is placed inside double-quotes, an attacker can use a double-quote character to terminate the string and inject arbitrary shell syntax. Since the PAM stack executes popen() with root privileges, a local attacker can achieve privilege escalation to root without possessing the required physical USB device. This issue is fixed in version 0.8.7 by implementing strict validation of the socket path and client ID.
Affected products
- mcdope pam_usb < 0.8.7
Timeline
- 2026-05-07: advisory: GitHub Security Advisory published
- 2026-05-27: disclosed: CVE published to NVD