Denial of Remote Session Validation in pam_usb for Linux by MCDope
CVE-2026-47270
6.3MEDIUM
What is CVE-2026-47270?
The pam_usb module, which facilitates hardware authentication in Linux, contains a vulnerability that can lead to incorrect parsing of authentication requests due to a race condition in its multi-threaded environment. Prior to version 0.9.0, concurrent authentication attempts can overwrite each other's state, affecting the deny_remote feature. This may result in improper decisions regarding remote and local session authentications, potentially allowing unauthorized access. The issue has been rectified in version 0.9.0.
Affected Version(s)
pam_usb < 0.9.0
