Skip to content

XML_PARSE_NOENT in xmlReadFile() enables file:// XXE; original no-flag call permitted full XXE (conf.c)

Moderate
mcdope published GHSA-96vv-r4wc-28c2 May 24, 2026

Software

pam_usb

Affected versions

<= 0.8.6

Patched versions

None

Description

pam_usb's pusb_conf_parse() in src/conf.c calls xmlReadFile() to load the configuration file.

Original vulnerability (flags=0): No parser flags were passed to xmlReadFile(), allowing libxml2 to process external entity references without restriction. This permitted both network-URI (http://, ftp://) and local file:// entity loads at XML parse time from the context of the authenticating process (setuid, running as root in sudo/su contexts).

Incomplete/incorrect initial fix (#385): The fix passed XML_PARSE_NONET | XML_PARSE_NOENT to xmlReadFile(). XML_PARSE_NONET correctly blocks network-URI entity fetches. However, XML_PARSE_NOENT — defined by libxml2 as "substitute entities" — enables entity substitution, not prevents it. The flag was added under the mistaken belief that it would cause NONET-blocked references to expand to empty content. In reality it has no bearing on how blocked entities are handled, and actively enables substitution of file:// entities that XML_PARSE_NONET does not block. The accompanying code comment explaining this reasoning was therefore factually incorrect. This was pointed out by Nick Wellnhof (ex-libxml2 maintainer) after the fix was merged.

Correct fix (#442): Pass only XML_PARSE_NONET. Without XML_PARSE_NOENT, entity references are never substituted into the parsed tree — they remain as inert entity-reference nodes that XPath text() queries do not yield. Network entities are blocked by NONET; file:// entities are neutralised by the absence of NOENT. Normal pamusb.conf files (generated by pamusb-conf) never contain entity declarations, so removing the flag has no impact on real-world operation.

Practical exploitability: Injecting an XXE payload requires write access to /etc/pamusb.conf, which is root-owned. An attacker with that access has already achieved full system compromise. The impact is defence-in-depth: pam_usb runs in setuid contexts and must not make unexpected outbound connections or file reads driven by config content.

Severity

Moderate

CVSS overall score

This score calculates overall vulnerability severity from 0 to 10 and is based on the Common Vulnerability Scoring System (CVSS).
/ 10

CVSS v3 base metrics

Attack vector
Local
Attack complexity
High
Privileges required
High
User interaction
None
Scope
Changed
Confidentiality
High
Integrity
Low
Availability
Low

CVSS v3 base metrics

Attack vector: More severe the more the remote (logically and physically) an attacker can be in order to exploit the vulnerability.
Attack complexity: More severe for the least complex attacks.
Privileges required: More severe if no privileges are required.
User interaction: More severe when no user interaction is required.
Scope: More severe when a scope change occurs, e.g. one vulnerable component impacts resources in components beyond its security scope.
Confidentiality: More severe when loss of data confidentiality is highest, measuring the level of data access available to an unauthorized user.
Integrity: More severe when loss of data integrity is the highest, measuring the consequence of data modification possible by an unauthorized user.
Availability: More severe when the loss of impacted component availability is highest.
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:L

CVE ID

CVE-2026-48981

Weaknesses

Improper Restriction of XML External Entity Reference

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output. Learn more on MITRE.

Credits