CVE-2020-24612

MEDIUM

selinux-policy <2020-08-24 - Privilege Escalation

Title source: llm
STIX 2.1

Description

An issue was discovered in the selinux-policy (aka Reference Policy) package 3.14 through 2020-08-24 because the .config/Yubico directory is mishandled. Consequently, when SELinux is in enforced mode, pam-u2f is not allowed to read the user's U2F configuration file. If configured with the nouserok option (the default when configured by the authselect tool), and that file cannot be read, the second factor is disabled. An attacker with only the knowledge of the password can then log in, bypassing 2FA.

References (2)

Core 2
Core References
Issue Tracking, Third Party Advisory x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=1860888

Scores

CVSS v3 6.7
EPSS 0.0032
EPSS Percentile 23.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Details

CWE
CWE-287
Status published
Products (1)
fedoraproject/selinux-policy 3.14 - 2020-08-24
Published Aug 24, 2020
Tracked Since Feb 18, 2026