The PAM module for fscrypt doesnt adequately validate fscrypt metadata files, allowing users to create malicious metadata files that prevent other users from logging in. A local user can cause a denial of service by creating a fscrypt metadata file that prevents other users from logging into the system. We recommend upgrading to version 0.3.3 or above
Name | Vendor | Start Version | End Version |
---|---|---|---|
Fscrypt | * | 0.3.3 (excluding) | |
Fscrypt | Ubuntu | bionic | * |
Fscrypt | Ubuntu | esm-apps/bionic | * |
Fscrypt | Ubuntu | esm-apps/focal | * |
Fscrypt | Ubuntu | focal | * |
Fscrypt | Ubuntu | impish | * |
Fscrypt | Ubuntu | trusty | * |
Fscrypt | Ubuntu | upstream | * |
Fscrypt | Ubuntu | xenial | * |