CVE Explorer
CVE-2026-48986
pam_usb provides hardware authentication for Linux using removable media. In pam_usb 0.9.1 and earlier, usb_get_process_parent_id() can cause an infinite loop DoS because it does not initialize *ppid on failure. In pusb_local_login(), the same variable is reused as input and output in a process-tree while loop; if /proc/<pid>/stat cannot be read (for example, when an ancestor process exits during authentication), the PID is not updated and the loop does not terminate. This hangs the authenticati
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"pam_usb","vendor":"mcdope","versions":[{"status":"affected","version":"< 0.9.2"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:12c46cf97176708cb3ed717ab41270134f69293bb7f518001cb3f20132250be7 · sha256:6c750fd3215570a1… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":4.7,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:12c46cf97176708cb3ed717ab41270134f69293bb7f518001cb3f20132250be7 · sha256:6c750fd3215570a1… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-835","description":"CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:12c46cf97176708cb3ed717ab41270134f69293bb7f518001cb3f20132250be7 · sha256:6c750fd3215570a1… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/mcdope/pam_usb/releases/tag/0.9.2","tags":["x_refsource_MISC"],"url":"https://github.com/mcdope/pam_usb/releases/tag/0.9.2"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:12c46cf97176708cb3ed717ab41270134f69293bb7f518001cb3f20132250be7 · sha256:6c750fd3215570a1… · /containers/cna/references/1
{"name":"https://github.com/mcdope/pam_usb/security/advisories/GHSA-h28h-9hc3-v595","tags":["x_refsource_CONFIRM"],"url":"https://github.com/mcdope/pam_usb/security/advisories/GHSA-h28h-9hc3-v595"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:12c46cf97176708cb3ed717ab41270134f69293bb7f518001cb3f20132250be7 · sha256:6c750fd3215570a1… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.