Executive brief
pam_usb is a tool that allows users to log into Linux systems using a physical USB drive as a security key. A flaw in how the software checks for these security keys allows a local user to bypass the hardware requirement entirely by deleting a specific file in their home directory. This effectively disables the multi-factor authentication, allowing unauthorized access to the system without the required physical USB device.
Technical details
The vulnerability exists in the pusb_pad_compare() function within src/pad.c of pam_usb. The function fails to enforce that the system-side pad (stored on the USB device) is present and readable, only verifying the user-side pad (~/.pamusb/device.pad). If the user-side pad is missing or unreadable, the function returns a failure that is treated as non-fatal in certain code paths, allowing authentication to proceed without verifying the physical hardware. Additionally, a secondary issue involves the use of uninitialized stack memory when generating random pads if /dev/random fails to provide sufficient bytes. These issues are addressed in version 0.9.0 by implementing symmetrical pad verification and switching to getrandom(2).
Affected products
- mcdope pam_usb < 0.9.0
Timeline
- 2026-05-20: advisory: GitHub Security Advisory published
- 2026-05-27: disclosed: CVE published to NVD