Summary
src/device.c passed the return values of udisks_drive_get_serial(), udisks_drive_get_vendor(), and udisks_drive_get_model() directly to strcmp() without NULL checks:
retval = strcmp(udisks_drive_get_serial(drive),
opts->device_list[currentDevice].serial) == 0;
retval = retval && strcmp(udisks_drive_get_vendor(drive), ...) == 0;
retval = retval && strcmp(udisks_drive_get_model(drive), ...) == 0;
The GIO/UDisks API documentation states these accessors can return NULL for devices that do not expose the corresponding field. Passing NULL to strcmp() is undefined behaviour (typically a SIGSEGV).
Impact
An attacker with physical access can plug in a USB device (or mass-storage gadget) that exposes no serial number via UDisks. The PAM module crashes during device enumeration, causing authentication to fail for all users on the affected service until the device is removed. On a single-user workstation with only pam_usb configured for login this results in a complete lockout.
Affected versions
pam_usb <= 0.8.6
Fix
NULL checks added before all three strcmp() calls in pusb_device_check(). A NULL serial, vendor, or model causes the drive to be skipped (treated as non-matching) rather than crashing.
Fix committed in d9acb56 (src/device.c).
Summary
src/device.cpassed the return values ofudisks_drive_get_serial(),udisks_drive_get_vendor(), andudisks_drive_get_model()directly tostrcmp()without NULL checks:The GIO/UDisks API documentation states these accessors can return
NULLfor devices that do not expose the corresponding field. PassingNULLtostrcmp()is undefined behaviour (typically aSIGSEGV).Impact
An attacker with physical access can plug in a USB device (or mass-storage gadget) that exposes no serial number via UDisks. The PAM module crashes during device enumeration, causing authentication to fail for all users on the affected service until the device is removed. On a single-user workstation with only
pam_usbconfigured for login this results in a complete lockout.Affected versions
pam_usb <= 0.8.6
Fix
NULL checks added before all three
strcmp()calls inpusb_device_check(). ANULLserial, vendor, or model causes the drive to be skipped (treated as non-matching) rather than crashing.Fix committed in
d9acb56(src/device.c).