CVE-2022-25326
published 2022-02-25CVE-2022-25326: fscrypt through v0.3.2 creates a world-writable directory by default when setting up a filesystem, allowing unprivileged users to exhaust filesystem space. We…
PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.13%
3.0th percentile
fscrypt through v0.3.2 creates a world-writable directory by default when setting up a filesystem, allowing unprivileged users to exhaust filesystem space. We recommend upgrading to fscrypt 0.3.3 or above and adjusting the permissions on existing fscrypt metadata directories where applicable.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | fscrypt | < fscrypt 0.3.3-1 (bookworm) | fscrypt 0.3.3-1 (bookworm) |
| github.com | google_fscrypt | >= 0 < 0.3.3 | 0.3.3 |
| fscrypt | <= 0.3.2 | — | |
| fscrypt | >= 0 < 0.3.3-1 | 0.3.3-1 | |
| fscrypt | >= 0 < 0.3.3-1 | 0.3.3-1 | |
| fscrypt | >= 0 < 0.3.3-1 | 0.3.3-1 | |
| google_llc | fscrypt | unspecified – 0.3.2 | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
ghsa5.5MEDIUM
osv5.5MEDIUM
vendor_debian5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Possible filesystem space exhaustion by local users in github.com/google/fscrypt
osv·2024-08-21
CVE-2022-25326 Possible filesystem space exhaustion by local users in github.com/google/fscrypt
Possible filesystem space exhaustion by local users in github.com/google/fscrypt
Possible filesystem space exhaustion by local users in github.com/google/fscrypt
GHSA
Possible filesystem space exhaustion by local users
ghsa·2022-03-01·CVSS 5.5
CVE-2022-25326 [MEDIUM] Possible filesystem space exhaustion by local users
Possible filesystem space exhaustion by local users
`fscrypt` through v0.3.2 creates a world-writable directory by default when setting up a filesystem, allowing unprivileged users to exhaust filesystem space. We recommend upgrading to `fscrypt` v0.3.3 or above and adjusting the permissions on existing `fscrypt` metadata directories where applicable.
For more details, see [CVE-2022-25326](https://www.cve.org/CVERecord?id=CVE-2022-25326) and https://github.com/google/fscrypt#setting-up-fscrypt-on-a-filesystem.
OSV
Possible filesystem space exhaustion by local users
osv·2022-03-01·CVSS 5.5
CVE-2022-25326 [MEDIUM] Possible filesystem space exhaustion by local users
Possible filesystem space exhaustion by local users
`fscrypt` through v0.3.2 creates a world-writable directory by default when setting up a filesystem, allowing unprivileged users to exhaust filesystem space. We recommend upgrading to `fscrypt` v0.3.3 or above and adjusting the permissions on existing `fscrypt` metadata directories where applicable.
For more details, see [CVE-2022-25326](https://www.cve.org/CVERecord?id=CVE-2022-25326) and https://github.com/google/fscrypt#setting-up-fscrypt-on-a-filesystem.
OSV
Uncontrolled Resource Consumption in github.com/google/fscrypt
osv·2022-02-26
CVE-2022-25326 [MEDIUM] Uncontrolled Resource Consumption in github.com/google/fscrypt
Uncontrolled Resource Consumption in github.com/google/fscrypt
fscrypt through v0.3.2 creates a world-writable directory by default when setting up a filesystem, allowing unprivileged users to exhaust filesystem space. We recommend upgrading to fscrypt 0.3.3 or above and adjusting the permissions on existing fscrypt metadata directories where applicable.
GHSA
Uncontrolled Resource Consumption in github.com/google/fscrypt
ghsa·2022-02-26
CVE-2022-25326 [MEDIUM] CWE-400 Uncontrolled Resource Consumption in github.com/google/fscrypt
Uncontrolled Resource Consumption in github.com/google/fscrypt
fscrypt through v0.3.2 creates a world-writable directory by default when setting up a filesystem, allowing unprivileged users to exhaust filesystem space. We recommend upgrading to fscrypt 0.3.3 or above and adjusting the permissions on existing fscrypt metadata directories where applicable.
OSV
CVE-2022-25326: fscrypt through v0
osv·2022-02-25·CVSS 5.5
CVE-2022-25326 [MEDIUM] CVE-2022-25326: fscrypt through v0
fscrypt through v0.3.2 creates a world-writable directory by default when setting up a filesystem, allowing unprivileged users to exhaust filesystem space. We recommend upgrading to fscrypt 0.3.3 or above and adjusting the permissions on existing fscrypt metadata directories where applicable.
Debian
CVE-2022-25326: fscrypt - fscrypt through v0.3.2 creates a world-writable directory by default when settin...
vendor_debian·2022·CVSS 5.5
CVE-2022-25326 [MEDIUM] CVE-2022-25326: fscrypt - fscrypt through v0.3.2 creates a world-writable directory by default when settin...
fscrypt through v0.3.2 creates a world-writable directory by default when setting up a filesystem, allowing unprivileged users to exhaust filesystem space. We recommend upgrading to fscrypt 0.3.3 or above and adjusting the permissions on existing fscrypt metadata directories where applicable.
Scope: local
bookworm: resolved (fixed in 0.3.3-1)
bullseye: open
forky: resolved (fixed in 0.3.3-1)
sid: resolved (fixed in 0.3.3-1)
trixie: resolved (fixed in 0.3.3-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-02-25
Published