CVE-2026-44711 PUBLISHED

pam_usb: Symlink attacks on pad directory and pad files enable authentication bypass and root file corruption

Assigner: GitHub_M
Reserved: 07.05.2026 Published: 27.05.2026 Updated: 28.05.2026

pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, symlink attacks on pad directory and pad files enable authentication bypass and root file corruption. This vulnerability is fixed in 0.8.7.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H
CVSS Score: 7.9

Product Status

Vendor mcdope
Product pam_usb
Versions
  • Version < 0.8.7 is affected

References

Problem Types

  • CWE-59: Improper Link Resolution Before File Access ('Link Following') CWE
  • CWE-287: Improper Authentication CWE