SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-25327

The PAM module for fscrypt doesn't adequately validate fscrypt metadata files, allowing users to create malicious metadata files that prevent other users from logging in.

MEDIUM 5.5EPSS 0.11%

Does this matter?

Lower severity and a low EPSS score (0.11%). Track it; it rarely justifies an emergency change on its own.

Description

The PAM module for fscrypt doesn't adequately validate fscrypt metadata files, allowing users to create malicious metadata files that prevent other users from logging in. A local user can cause a denial of service by creating a fscrypt metadata file that prevents other users from logging into the system. We recommend upgrading to version 0.3.3 or above

CVSS 3.1
5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS
0.11% probability · 2th percentile
CISA KEV
Not listed
Weakness
CWE-255, CWE-276
Affected
google/fscrypt
Source
cve-coordination@google.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.