CVE-2020-36394: Pam Setquota Project Pam Setquota
High severity, CVSS 7.0. EPSS: 0.3% chance of exploitation in the next 30 days.
pam_setquota.c in the pam_setquota module before 2020-05-29 for Linux-PAM allows local attackers to set their quota on an arbitrary filesystem, in certain situations where the attacker's home directory is a FUSE filesystem mounted under /home.
Affected products
- Pam Setquota Project Pam Setquota: before 2020-05-29 (fixed in 2020-05-29)
Published 2021-06-22. Last modified 2026-06-17.