An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges, the tss user still has read and write access to the /etc/tcsd.conf file (which contains various settings related to this daemon).
https://sourceforge.net/p/trousers/mailman/message/37015817/
https://seclists.org/oss-sec/2020/q2/att-135/tcsd_fixes.patch