Summary
Two vulnerabilities in the one-time pad (OTP) mechanism allow an attacker to bypass USB authentication or corrupt pad data.
Vulnerability 1 - Missing system pad allows authentication bypass (F3, High)
The pusb_pad_compare() function in src/pad.c only verified that the user-side pad (~/.pamusb/device.pad) could be read, but did not enforce that the system-side pad (the pad file on the USB device) was also present and readable. If the user-side pad was deleted or unreadable, the function returned a failure that was treated as non-fatal in certain code paths, allowing authentication to succeed without the USB device being verified.
A local user can delete their own ~/.pamusb/device.pad to remove the USB device requirement and authenticate without the physical device.
Vulnerability 2 - Uninitialized buffer written to pad on RNG failure (F2, High)
The original generateRandom() function in src/pad.c used fread() from /dev/random to fill pad magic buffers. If the read returned fewer bytes than expected (partial read or failure), the remainder of the buffer was left uninitialized (stack memory). This uninitialized data was then written to pad files and used in subsequent comparisons. Under error conditions this could produce predictable or attacker-influenced pad values.
Fix
Fixed in commit 275f0eb (PR #303). Both pads are now verified symmetrically. Random bytes are generated via getrandom(2) which guarantees exact-length fills or explicit failure. Pad buffers are zeroed with explicit_bzero() before use and after comparison.
Summary
Two vulnerabilities in the one-time pad (OTP) mechanism allow an attacker to bypass USB authentication or corrupt pad data.
Vulnerability 1 - Missing system pad allows authentication bypass (F3, High)
The pusb_pad_compare() function in src/pad.c only verified that the user-side pad (~/.pamusb/device.pad) could be read, but did not enforce that the system-side pad (the pad file on the USB device) was also present and readable. If the user-side pad was deleted or unreadable, the function returned a failure that was treated as non-fatal in certain code paths, allowing authentication to succeed without the USB device being verified.
A local user can delete their own ~/.pamusb/device.pad to remove the USB device requirement and authenticate without the physical device.
Vulnerability 2 - Uninitialized buffer written to pad on RNG failure (F2, High)
The original generateRandom() function in src/pad.c used fread() from /dev/random to fill pad magic buffers. If the read returned fewer bytes than expected (partial read or failure), the remainder of the buffer was left uninitialized (stack memory). This uninitialized data was then written to pad files and used in subsequent comparisons. Under error conditions this could produce predictable or attacker-influenced pad values.
Fix
Fixed in commit 275f0eb (PR #303). Both pads are now verified symmetrically. Random bytes are generated via getrandom(2) which guarantees exact-length fills or explicit failure. Pad buffers are zeroed with explicit_bzero() before use and after comparison.