Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 18 Jun 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mcdope
Mcdope pam Usb |
|
| Vendors & Products |
Mcdope
Mcdope pam Usb |
|
| Metrics |
ssvc
|
Thu, 18 Jun 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | pam_usb provides hardware authentication for Linux using removable media. In versions prior to 0.9.2, getenv() environment variables XRDP_SESSION, DISPLAY and TMUX allow environment variable injection into local-check logic. These environment variables influence whether a current session is local or remote, and a PAM module that runs in the context of setuid binaries (sudo, su), getenv() returns attacker-controlled values whenever the process environment has been manipulated by a local user. This issue has been fixed in version 0.9.2. | |
| Title | pam_usb: getenv() used in PAM context allows environment variable injection into local-check logic | |
| Weaknesses | CWE-454 CWE-807 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-18T20:25:31.988Z
Reserved: 2026-05-26T23:26:07.974Z
Link: CVE-2026-48980
Updated: 2026-06-18T20:25:26.727Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-18T21:30:16Z