CVE-2026-48980CWE-454CWE-807

pam_usb: getenv() used in PAM context allows environment variable injection into local-check logic

Medium · published June 18, 2026

CVSS v3.1
6.3
EPSS
0%
Percentile
7.2
In the wild
Unconfirmed
What it is

pam_usb provides hardware authentication for Linux using removable media. In versions prior to 0.9.2, getenv() environment variables XRDP_SESSION, DISPLAY and TMUX allow environment variable injection into local-check logic. These environment variables influence whether a current session is local or remote, and a PAM module that runs in the context of setuid binaries (sudo, su), getenv() returns attacker-controlled values whenever the process environment has been manipulated by a local user. This issue has been fixed in version 0.9.2.

The record
Technical detail
CVSS v3.1
6.3 · MEDIUM
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
CVSS v4.0
Not supplied
EPSS
0.00175 · 7.2th percentile
Weaknesses
CWE-454 · External Initialization of Trusted Variables or Data Stores; CWE-807 · Reliance on Untrusted Inputs in a Security Decision
Published
2026-06-18T19:26Z
EPSS history
Timeline
  • 18 JUN 19:26Z
    pam_usb: getenv() used in PAM context allows environment variable injection into local-check logic
    cvelistv5