pamusb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.1, when a PAM service is configured with denyremote=false in pamusb (commonly done for display managers such as gdm-password or lightdm to bypass process/TTY heuristics for local sessions), the PAMRHOST check in pusbdoauth() is also skipped. PAMRHOST is set by remote daemons (sshd, XDMCP servers) to identify the remote client address. Because the check is gated inside if (opts.denyremote), a genuine remote XDMCP connection reaches the USB device authentication step instead of being rejected. This vulnerability is fixed in 0.9.1.
{
"cwe_ids": [
"CWE-863"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/48xxx/CVE-2026-48064.json",
"cna_assigner": "GitHub_M"
}[
{
"source": "https://github.com/mcdope/pam_usb/commit/e2f30b22cd0715fcde0fc62d6ee3e1ca6370b8a9",
"signature_version": "v1",
"signature_type": "Line",
"digest": {
"line_hashes": [
"32897324108646938673138056869665931337"
],
"threshold": 0.9
},
"deprecated": false,
"id": "CVE-2026-48064-b792a2ae",
"target": {
"file": "src/version.h"
}
}
]
"2026-07-15T23:39:34Z"
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-48064.json"