PT-2022-17214 · Fscrypt+2 · Fscrypt+2

Matthias Gerstner

·

Published

2022-02-25

·

Updated

2024-08-21

·

CVE-2022-25326

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions fscrypt versions through 0.3.2
Description The issue allows unprivileged users to exhaust filesystem space due to a world-writable directory created by default when setting up a filesystem.
Recommendations For fscrypt versions through 0.3.2, upgrade to fscrypt 0.3.3 or above and adjust the permissions on existing fscrypt metadata directories where applicable.

Fix

Resource Exhaustion

Weakness Enumeration

Related Identifiers

ALT-PU-2023-1941
CVE-2022-25326
GHSA-CHXF-FJCF-7FWP
GHSA-MPQ4-RJJ8-FJPH
GO-2022-0339
OPENSUSE-SU-2024:11902-1

Affected Products

Alt Linux
Debian
Fscrypt