PT-2026-50769 · Pam Usb · Pam Usb
CVSS v3.1
4.7
Medium
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
pam usb versions 0.9.1 and earlier
Description
The
xfree() memory release helper calls free() without zeroing buffer contents first. This results in heap-allocated buffers containing sensitive data, such as one-time pad bytes read from disk, being released without being cleared. Consequently, sensitive content remains in freed heap memory until overwritten by a subsequent allocation. In scenarios where a heap inspection primitive is available or a use-after-free condition exists, this could allow the recovery of authentication material or pad values from freed memory regions.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pam Usb