Executive brief
pam_usb is a tool that allows users to log into Linux systems using a USB drive as a physical key. A security flaw in how it checks for local versus remote sessions could allow a local attacker to trick the system into misidentifying their connection type. This could potentially be used to bypass security policies or gain unauthorized access to administrative functions like sudo.
Technical details
The pam_usb module incorrectly utilizes the getenv() function to retrieve environment variables such as XRDP_SESSION, DISPLAY, and TMUX to determine if a session is local or remote. Because PAM modules often execute within the context of setuid binaries (like sudo or su), a local attacker can manipulate the process environment to inject these variables. This reliance on untrusted inputs in a security decision (CWE-807) allows an attacker to influence the 'local-check' logic. The vulnerability is resolved in version 0.9.2 by replacing getenv() with secure_getenv(), which returns NULL when the effective UID does not match the real UID.
Affected products
- mcdope pam_usb < 0.9.2
Timeline
- 2026-05-23: patched: Version 0.9.2 released
- 2026-05-24: advisory: GitHub Security Advisory published
- 2026-06-18: disclosed: CVE-2026-48980 published to NVD