CVE 7.9 HIGH

pam_usb: Symlink attacks on pad directory and pad files enable authentication bypass and root file corruption_CVE-2026-44711

7.9 / 10
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H

Description

pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, symlink attacks on pad directory and pad files enable authentication bypass and root file corruption. This vulnerability is fixed in 0.8.7.

Basic Information

ID CVE-2026-44711
Source GitHub_M
Published May 27, 2026 at 20:18

Affected Product

Vendor mcdope
Product pam_usb
Version < 0.8.7
Affected Versions mcdope pam_usb < 0.8.7

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.