Vulnerability Description
The PAM module for fscrypt doesn't adequately validate fscrypt metadata files, allowing users to create malicious metadata files that prevent other users from logging in. A local user can cause a denial of service by creating a fscrypt metadata file that prevents other users from logging into the system. We recommend upgrading to version 0.3.3 or above
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fscrypt | < 0.3.3 |
Related Weaknesses (CWE)
References
- https://github.com/google/fscrypt/pull/346PatchThird Party Advisory
- https://github.com/google/fscrypt/pull/346PatchThird Party Advisory
FAQ
What is CVE-2022-25327?
CVE-2022-25327 is a vulnerability with a CVSS score of 5.5 (MEDIUM). The PAM module for fscrypt doesn't adequately validate fscrypt metadata files, allowing users to create malicious metadata files that prevent other users from logging in. A local user can cause a deni...
How severe is CVE-2022-25327?
CVE-2022-25327 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-25327?
Check the references section above for vendor advisories and patch information. Affected products include: Google Fscrypt.