CVE-2026-48986: CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop') in mcdope pam_usb
pam_usb provides hardware authentication for Linux using removable media. In pam_usb 0.9.1 and earlier, usb_get_process_parent_id() can cause an infinite loop DoS because it does not initialize *ppid on failure. In pusb_local_login(), the same variable is reused as input and output in a process-tree while loop; if /proc/<pid>/stat cannot be read (for example, when an ancestor process exits during authentication), the PID is not updated and the loop does not terminate. This hangs the authenticating process (such as sudo, sshd, or login) until it is forcibly terminated. This issue has been fixed in version 0.9.2.
AI Analysis
Technical Summary
In pam_usb 0.9.1 and earlier, the function usb_get_process_parent_id() does not initialize the parent process ID variable on failure. Subsequently, in pusb_local_login(), this variable is reused in a loop that traverses the process tree. If the process stat file cannot be read (e.g., if an ancestor process exits during authentication), the PID variable is not updated, causing the loop to never exit and resulting in a denial of service via an infinite loop. This vulnerability has been addressed in pam_usb version 0.9.2.
Potential Impact
An attacker or environmental condition causing failure to read /proc/<pid>/stat can trigger an infinite loop in the authentication process, causing it to hang indefinitely. This results in a denial of service affecting authentication mechanisms such as sudo, sshd, or login. There is no impact on confidentiality or integrity.
Mitigation Recommendations
Upgrade pam_usb to version 0.9.2 or later, where this infinite loop issue is fixed. Patch status is not explicitly stated in the vendor advisory, but the fix is included in version 0.9.2. Until upgraded, be aware that authentication processes may hang under certain conditions.
CVE-2026-48986: CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop') in mcdope pam_usb
Description
pam_usb provides hardware authentication for Linux using removable media. In pam_usb 0.9.1 and earlier, usb_get_process_parent_id() can cause an infinite loop DoS because it does not initialize *ppid on failure. In pusb_local_login(), the same variable is reused as input and output in a process-tree while loop; if /proc/<pid>/stat cannot be read (for example, when an ancestor process exits during authentication), the PID is not updated and the loop does not terminate. This hangs the authenticating process (such as sudo, sshd, or login) until it is forcibly terminated. This issue has been fixed in version 0.9.2.
CVSS v3.1
Score 4.7medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
In pam_usb 0.9.1 and earlier, the function usb_get_process_parent_id() does not initialize the parent process ID variable on failure. Subsequently, in pusb_local_login(), this variable is reused in a loop that traverses the process tree. If the process stat file cannot be read (e.g., if an ancestor process exits during authentication), the PID variable is not updated, causing the loop to never exit and resulting in a denial of service via an infinite loop. This vulnerability has been addressed in pam_usb version 0.9.2.
Potential Impact
An attacker or environmental condition causing failure to read /proc/<pid>/stat can trigger an infinite loop in the authentication process, causing it to hang indefinitely. This results in a denial of service affecting authentication mechanisms such as sudo, sshd, or login. There is no impact on confidentiality or integrity.
Mitigation Recommendations
Upgrade pam_usb to version 0.9.2 or later, where this infinite loop issue is fixed. Patch status is not explicitly stated in the vendor advisory, but the fix is included in version 0.9.2. Until upgraded, be aware that authentication processes may hang under certain conditions.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-26T23:26:07.975Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a343000f198dc38c1384725
Added to database: 06/18/2026, 17:50:56 UTC
Last enriched: 06/25/2026, 21:18:46 UTC
Last updated: 08/01/2026, 19:18:00 UTC
Views: 70
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.