Executive brief
pam_usb is a tool that allows users to log into Linux systems using a physical USB drive as a security key. A flaw in its remote-access protection allows attackers to bypass security restrictions when connecting over a network via SSH. If an attacker has physical access to a registered USB device, they can use it to log into a remote server even if the system is configured to block remote USB authentication, potentially leading to unauthorized access to sensitive data and systems.
Technical details
A vulnerability exists in pam_usb's 'deny_remote' feature due to an incomplete check of the utmpx ut_addr_v6 field. The software originally only validated the first 32-bit word of the 128-bit IPv6 address field to detect remote sessions. Because IPv4-mapped IPv6 addresses (::ffff:x.x.x.x) store the address data in the final word and leave the first word as zero, remote connections on systems using IPv6 wildcards (common in Debian/Ubuntu SSH configurations) are misclassified as local. An attacker with physical access to a registered USB device can exploit this to authenticate via SSH, bypassing the intended remote-access block. This issue is resolved in version 0.9.0 by ensuring all four words of the address field are checked.
Affected products
- mcdope pam_usb < 0.9.0
Timeline
- 2026-05-20: advisory: GitHub Security Advisory published
- 2026-05-27: disclosed: CVE-2026-47269 published to NVD
- 2026-05-27: patched: Fixed in version 0.9.0