Junglewise Threat Intelligence

CVE-2026-47270: pam_usb race condition in remote session detection

CVE-2026-47270 · Severity: medium · CVSS 6.3 · Published 2026-05-27

Technologies: Mcdope Pam Usb. Vendors: Mcdope.

Executive brief

pam_usb is a tool that allows users to log into Linux systems using a USB drive as a physical key. A flaw in how the software handles multiple login attempts at once can cause it to incorrectly identify whether a user is logging in locally or remotely. This could allow an attacker to bypass security restrictions intended to block remote access, potentially gaining unauthorized entry to the system.

Technical details

The pam_usb module prior to version 0.9.0 utilizes the non-reentrant strtok() function in three critical functions: pusb_tmux_get_client_tty(), pusb_tmux_has_remote_clients(), and pusb_get_process_envvar(). Because strtok() uses a global static pointer, concurrent authentication threads in display managers like GDM can cause race conditions that corrupt the tokenization state. This leads to incorrect parsing of tmux session data or /proc environment scans used for remote-session detection. Furthermore, the module incorrectly passed pointers from getenv() directly to strtok(), causing permanent corruption of the process environment block by inserting NUL bytes. These issues can result in the 'deny_remote' feature failing to block remote sessions or incorrectly blocking local ones. The vulnerability is fixed in version 0.9.0 by migrating to strtok_r() and using private heap copies of environment variables.

Affected products

  • mcdope pam_usb < 0.9.0

Timeline

  • 2026-05-17: patched: Fixes committed to repository
  • 2026-05-20: advisory: GitHub Security Advisory published
  • 2026-05-27: disclosed: CVE published to NVD

References

Related threats