{"id":"CVE-2020-24455","details":"Missing initialization of a variable in the TPM2 source may allow a privileged user to potentially enable an escalation of privilege via local access. This affects tpm2-tss before 3.0.1 and before 2.4.3.","modified":"2026-07-07T08:51:35.765458238Z","published":"2021-02-26T03:15:12.213Z","related":["openSUSE-SU-2024:11470-1"],"database_specific":{"unresolved_ranges":[{"extracted_events":[{"introduced":"34"},{"last_affected":"34"}],"source":"CPE_STRING","vendor_product":"fedoraproject:fedora","cpes":["cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*"]}]},"references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7KPOENCMJU4DMT3BDNUBRK25B3DJ47UO/"},{"type":"ADVISORY","url":"https://github.com/tpm2-software/tpm2-tss/releases/tag/2.4.3"},{"type":"ADVISORY","url":"https://github.com/tpm2-software/tpm2-tss/releases/tag/3.0.1"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/202107-10"},{"type":"FIX","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1902167"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/tpm2-software/tpm2-tss","events":[{"introduced":"0"},{"fixed":"14a0e029f9e6a507eaa8ece0b230a23ea8fa7dcb"},{"introduced":"0eee5c42fd06bfb36d351cb9f13c1c06a59d678b"},{"fixed":"f653b79868472ba7d3a9fa323ea8bce9137ea7d8"}],"database_specific":{"cpe":"cpe:2.3:a:tpm2_software_stack_project:tpm2_software_stack:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"2.4.3"},{"introduced":"3.0.0"},{"fixed":"3.0.1"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["3.0.0","2.4.2","2.4.1","2.4.0","2.0.0","1.0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-24455.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"}]}