CVE-2026-48792
pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.1, src/evdev.c silently ignores EACCES errors when opening /dev/input/event* nodes, causing pusb_has_virtual_input_device() to return 0 (no virtual devices found) even when every open() call failed due to insufficient permissions. The caller in src/local.c cannot distinguish a clean absence of virtual devices from a permission-denied scan, and acts on the false negative by continuing authentication without denying. This vulnerability is fixed in 0.9.1.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.4
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
- EPSS probability
- 0.13%
- CWE
- CWE-390, CWE-693
- Published
- 2026-05-27
- Last modified
- 2026-05-28
Affected products
- mcdope pam_usb
Weakness type
Related vulnerabilities
- CVE-2026-76642 — util-linux libmount Privilege Escalation via Failed Mount Helper
- CVE-2026-59845 — Libssh: libssh: denial of service via unchecked proxycommand fork() failure
- CVE-2026-53434 — Apache Tomcat: Invalid CRL configuration doesn't trigger failure for FFM Connector
- CVE-2026-44310 — gitsign --verify panics on empty-certificate PKCS7 and exits 0, bypassing exit-code callers
- CVE-2025-0029 — Improper handling of error condition during host-induced faults can allow a local high-privileged...
- CVE-2025-46367 — Dell Alienware Command Center 6.x (AWCC), versions prior to 6.10.15.0, contain a Detection of Error...
- CVE-2025-27039 — Detection of Error Condition Without Action in Computer Vision
- CVE-2024-49841 — Detection of Error Condition Without Action in Hypervisor