VYPR

pam_usb

by Pam Usb

CVEs (2)

  • CVE-2026-48980Jun 18, 2026
    risk 0.00cvss epss

    pam_usb provides hardware authentication for Linux using removable media. In versions prior to 0.9.2, getenv() environment variables XRDP_SESSION, DISPLAY and TMUX allow environment variable injection into local-check logic. These environment variables influence whether a…

  • CVE-2026-48981Jun 18, 2026
    risk 0.00cvss epss

    pam_usb provides hardware authentication for Linux using ordinary removable media. In versions prior to 0.9.2, pam_usb calls xmlReadFile() with flags=0 when loading the configuration file, allowing libxml2 to process external entity references (XXE), potentially making outbound…