CVE Vulnerabilities

CVE-2022-25327

Published: Feb 25, 2022 | Modified: Nov 21, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The PAM module for fscrypt doesnt adequately validate fscrypt metadata files, allowing users to create malicious metadata files that prevent other users from logging in. A local user can cause a denial of service by creating a fscrypt metadata file that prevents other users from logging into the system. We recommend upgrading to version 0.3.3 or above

Affected Software

NameVendorStart VersionEnd Version
FscryptGoogle*0.3.3 (excluding)
FscryptUbuntubionic*
FscryptUbuntuesm-apps/bionic*
FscryptUbuntuesm-apps/focal*
FscryptUbuntufocal*
FscryptUbuntuimpish*
FscryptUbuntutrusty*
FscryptUbuntuupstream*
FscryptUbuntuxenial*

References