CVE-2026-48980 | mcdope pam_usb up to 0.9.1 on Linux getenv external initialization (GHSA-qr83-mf3h-fvqr)
A vulnerability labeled as problematic has been found in mcdope pam_usb up to 0.9.1 on Linux. This affects the function getenv. The manipulation results in external initialization of trusted variables or data stores.
This vulnerability is known as CVE-2026-48980. Attacking locally is a requirement. No exploit is available.
The affected component should be upgraded.