pamusb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.0, pamusb's denyremote feature checks utmpx utaddrv6 to detect whether an authentication request originates from a remote session. The outer guard was if (utent->utaddrv6[0] != 0), which only tests the first 32-bit word of the 128-bit address field. IPv4-mapped IPv6 addresses (::ffff:x.x.x.x) store the IPv4 address in utaddrv6[3] with utaddrv6[0] == 0. On systems where the SSH daemon listens on :: (IPv6 wildcard) with AddressFamily any -- common on Ubuntu and Debian -- incoming IPv4 connections are recorded in utmpx as IPv4-mapped IPv6 addresses. The outer check evaluates to false, the remote-detection block is skipped entirely, and the session is treated as local. denyremote=true does not block the authentication. An attacker with physical access to a registered USB device can authenticate over SSH on an affected system as if they were sitting at a local terminal, bypassing the deny_remote restriction. This vulnerability is fixed in 0.9.0.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-284"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/47xxx/CVE-2026-47269.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-47269.json"
[
{
"target": {
"function": "pusb_is_tty_local",
"file": "src/local.c"
},
"deprecated": false,
"source": "https://github.com/mcdope/pam_usb/commit/804fe24eae3d742d8be05fd015e36abc3c7d94e5",
"id": "CVE-2026-47269-333ea212",
"signature_version": "v1",
"digest": {
"length": 1197.0,
"function_hash": "193037768944057422419939619927610672606"
},
"signature_type": "Function"
},
{
"target": {
"file": "src/local.c"
},
"deprecated": false,
"source": "https://github.com/mcdope/pam_usb/commit/804fe24eae3d742d8be05fd015e36abc3c7d94e5",
"id": "CVE-2026-47269-8bcbb116",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"253154704975797875645984500599312628330",
"191649508646307056564174506231220376710",
"159091127102520086978722006132133249113",
"334192888063606004618821418106347158964"
]
},
"signature_type": "Line"
},
{
"target": {
"file": "src/device.c"
},
"deprecated": false,
"source": "https://github.com/mcdope/pam_usb/commit/804fe24eae3d742d8be05fd015e36abc3c7d94e5",
"id": "CVE-2026-47269-c12870c8",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"111734613024512688401843346597624792554",
"32419240941865328615197713511651212359",
"133292760351448666045639736902550407643",
"186824676040192820982345094729142093606",
"337045630319195637586760951569068277075",
"321064616074521651917179242076711742811",
"102993289771242624379100828068961033442",
"175603995299463773467080808780259447995"
]
},
"signature_type": "Line"
},
{
"target": {
"function": "pusb_device_connected",
"file": "src/device.c"
},
"deprecated": false,
"source": "https://github.com/mcdope/pam_usb/commit/804fe24eae3d742d8be05fd015e36abc3c7d94e5",
"id": "CVE-2026-47269-e6ee68c0",
"signature_version": "v1",
"digest": {
"length": 2231.0,
"function_hash": "131945397491401008104677786559519543925"
},
"signature_type": "Function"
}
]
"2026-08-12T16:09:39Z"