Skip to content

OTP pad authentication bypass via missing system pad check and uninitialized RNG buffer

High
mcdope published GHSA-vx6f-rrqr-j87c May 20, 2026

Software

pam_usb

Affected versions

<= 0.8.6

Patched versions

0.9.0

Description

Summary

Two vulnerabilities in the one-time pad (OTP) mechanism allow an attacker to bypass USB authentication or corrupt pad data.

Vulnerability 1 - Missing system pad allows authentication bypass (F3, High)

The pusb_pad_compare() function in src/pad.c only verified that the user-side pad (~/.pamusb/device.pad) could be read, but did not enforce that the system-side pad (the pad file on the USB device) was also present and readable. If the user-side pad was deleted or unreadable, the function returned a failure that was treated as non-fatal in certain code paths, allowing authentication to succeed without the USB device being verified.

A local user can delete their own ~/.pamusb/device.pad to remove the USB device requirement and authenticate without the physical device.

Vulnerability 2 - Uninitialized buffer written to pad on RNG failure (F2, High)

The original generateRandom() function in src/pad.c used fread() from /dev/random to fill pad magic buffers. If the read returned fewer bytes than expected (partial read or failure), the remainder of the buffer was left uninitialized (stack memory). This uninitialized data was then written to pad files and used in subsequent comparisons. Under error conditions this could produce predictable or attacker-influenced pad values.

Fix

Fixed in commit 275f0eb (PR #303). Both pads are now verified symmetrically. Random bytes are generated via getrandom(2) which guarantees exact-length fills or explicit failure. Pad buffers are zeroed with explicit_bzero() before use and after comparison.

Severity

High

CVSS overall score

This score calculates overall vulnerability severity from 0 to 10 and is based on the Common Vulnerability Scoring System (CVSS).
/ 10

CVSS v3 base metrics

Attack vector
Local
Attack complexity
Low
Privileges required
Low
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None

CVSS v3 base metrics

Attack vector: More severe the more the remote (logically and physically) an attacker can be in order to exploit the vulnerability.
Attack complexity: More severe for the least complex attacks.
Privileges required: More severe if no privileges are required.
User interaction: More severe when no user interaction is required.
Scope: More severe when a scope change occurs, e.g. one vulnerable component impacts resources in components beyond its security scope.
Confidentiality: More severe when loss of data confidentiality is highest, measuring the level of data access available to an unauthorized user.
Integrity: More severe when loss of data integrity is the highest, measuring the consequence of data modification possible by an unauthorized user.
Availability: More severe when the loss of impacted component availability is highest.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

CVE ID

CVE-2026-47272

Weaknesses

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct. Learn more on MITRE.

Use of Uninitialized Resource

The product uses or accesses a resource that has not been initialized. Learn more on MITRE.

Credits