Google LLC Vulnerabilities and Affected Products
Vulnerabilities associated with fscrypt.
Products
Clear product- Asylo16 vulnerabilities
- Dart SDK4 vulnerabilities
- fscrypt3 vulnerabilities
- guest-oslogin3 vulnerabilities
- AWS S3 Crypto SDK for GoLang2 vulnerabilities
- Fuchsia2 vulnerabilities
- Fuchsia Kernel2 vulnerabilities
- libjxl2 vulnerabilities
- Android Play Core1 vulnerability
- Bazel1 vulnerability
- Bindiff1 vulnerability
- Brotli1 vulnerability
- Dart1 vulnerability
- Data-Transfer-Project1 vulnerability
- Drive for Desktop MacOS1 vulnerability
- Exposure Notifications Verification Server1 vulnerability
- Gerrit1 vulnerability
- go-attestation1 vulnerability
- Google Cloud IoT Device SDK for Embedded C1 vulnerability
- Google Earth Pro1 vulnerability
- Google Exposure-notifications-verification-server1 vulnerability
- Google Play Services SDK1 vulnerability
- Google-oauth-java-client1 vulnerability
- google-protobuf [JRuby Gem]1 vulnerability
- google/go-tpm library1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2022-25328MEDIUM | Privilege escalation through command injection in fscryptThe bash_completion script for fscrypt allows injection of commands via crafted mountpoint paths, allowing privilege escalation under a specific set of circumstances. A local user who has control over mountpoint paths could potentially escalate their privileges if they create a malicious mountpoint path and if the system administrator happens to be using the fscrypt bash completion script to complete mountpoint paths. We recommend upgrading to version 0.3.3 or above CWE-78Feb 25, 2022 | CVSS5.0v3.1 | EPSS0.202% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-25327MEDIUM | Local Denial of Service in fscrypt PAM moduleThe PAM module for fscrypt doesn't adequately validate fscrypt metadata files, allowing users to create malicious metadata files that prevent other users from logging in. A local user can cause a denial of service by creating a fscrypt metadata file that prevents other users from logging into the system. We recommend upgrading to version 0.3.3 or above | CVSS5.5v3.1 | EPSS0.112% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-25326MEDIUM | Denial of Service in fscryptfscrypt through v0.3.2 creates a world-writable directory by default when setting up a filesystem, allowing unprivileged users to exhaust filesystem space. We recommend upgrading to fscrypt 0.3.3 or above and adjusting the permissions on existing fscrypt metadata directories where applicable. CWE-400Feb 25, 2022 | CVSS5.5v3.1 | EPSS0.131% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |