Unrated severityNVD Advisory· Published Feb 26, 2021· Updated Aug 4, 2024
CVE-2020-24455
CVE-2020-24455
Description
Missing initialization of a variable in the TPM2 source may allow a privileged user to potentially enable an escalation of privilege via local access. This affects tpm2-tss before 3.0.1 and before 2.4.3.
Affected products
1- Range: before 3.01, before 2.4.3
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7KPOENCMJU4DMT3BDNUBRK25B3DJ47UO/mitrevendor-advisoryx_refsource_FEDORA
- security.gentoo.org/glsa/202107-10mitrevendor-advisoryx_refsource_GENTOO
- bugzilla.redhat.com/show_bug.cgimitrex_refsource_CONFIRM
- github.com/tpm2-software/tpm2-tss/releases/tag/2.4.3mitrex_refsource_CONFIRM
- github.com/tpm2-software/tpm2-tss/releases/tag/3.0.1mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.