{"id":"UBUNTU-CVE-2020-36394","details":"pam_setquota.c in the pam_setquota module before 2020-05-29 for Linux-PAM allows local attackers to set their quota on an arbitrary filesystem, in certain situations where the attacker's home directory is a FUSE filesystem mounted under /home.","modified":"2025-07-16T07:41:37.973130Z","published":"2021-06-22T21:15:00Z","withdrawn":"2025-07-18T16:46:17Z","upstream":["CVE-2020-36394"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2020-36394"},{"type":"REPORT","url":"https://seclists.org/oss-sec/2020/q2/169"},{"type":"REPORT","url":"https://github.com/linux-pam/linux-pam/commit/27ded8954a1235bb65ffc9c730ae5a50b1dfed61"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2020-36394"}],"affected":[{"package":{"name":"pam","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/pam@1.4.0-11ubuntu2?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.4.0-11ubuntu2"}]}],"versions":["1.3.1-5ubuntu11","1.4.0-10ubuntu1","1.4.0-10ubuntu2","1.4.0-11ubuntu1"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"libpam-cracklib","binary_version":"1.4.0-11ubuntu2"},{"binary_name":"libpam-cracklib-dbgsym","binary_version":"1.4.0-11ubuntu2"},{"binary_name":"libpam-doc","binary_version":"1.4.0-11ubuntu2"},{"binary_name":"libpam-modules","binary_version":"1.4.0-11ubuntu2"},{"binary_name":"libpam-modules-bin","binary_version":"1.4.0-11ubuntu2"},{"binary_name":"libpam-modules-bin-dbgsym","binary_version":"1.4.0-11ubuntu2"},{"binary_name":"libpam-modules-dbgsym","binary_version":"1.4.0-11ubuntu2"},{"binary_name":"libpam-runtime","binary_version":"1.4.0-11ubuntu2"},{"binary_name":"libpam0g","binary_version":"1.4.0-11ubuntu2"},{"binary_name":"libpam0g-dbgsym","binary_version":"1.4.0-11ubuntu2"},{"binary_name":"libpam0g-dev","binary_version":"1.4.0-11ubuntu2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2020/UBUNTU-CVE-2020-36394.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"low"}]}