top of page
perceptive_background_267k.jpg

pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, pamusb-pinentry reads the PINENTRY_FALLBACK_APP environment v…

Published:

26 May 2026 at 22:00:00

Alert date:

27 May 2026 at 22:02:45

Source:

nvd.nist.gov

Click to open the original link from this advisory

Operating Systems, Identity & Access

A vulnerability in pam_usb prior to version 0.8.7 allows arbitrary code execution through the PINENTRY_FALLBACK_APP environment variable. The pamusb-pinentry component executes the content of this environment variable without validation, enabling privilege escalation attacks. Any process that can set environment variables before pamusb-pinentry execution can exploit this flaw to run arbitrary binaries with pam_usb privileges. This affects the hardware authentication system for Linux that uses removable media for authentication.

Technical details

Mitigation steps:

Affected products:

pam_usb

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page