CVE-2022-25327
published 2022-02-25CVE-2022-25327: The PAM module for fscrypt doesn't adequately validate fscrypt metadata files, allowing users to create malicious metadata files that prevent other users from…
PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.11%
1.6th percentile
The PAM module for fscrypt doesn't adequately validate fscrypt metadata files, allowing users to create malicious metadata files that prevent other users from logging in. A local user can cause a denial of service by creating a fscrypt metadata file that prevents other users from logging into the system. We recommend upgrading to version 0.3.3 or above
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | fscrypt | < fscrypt 0.3.3-1 (bookworm) | fscrypt 0.3.3-1 (bookworm) |
| github.com | google_fscrypt | >= 0 < 0.3.3 | 0.3.3 |
| fscrypt | < 0.3.3 | 0.3.3 | |
| fscrypt | >= 0 < 0.3.3-1 | 0.3.3-1 | |
| fscrypt | >= 0 < 0.3.3-1 | 0.3.3-1 | |
| fscrypt | >= 0 < 0.3.3-1 | 0.3.3-1 | |
| google_llc | fscrypt | unspecified – 0.3.2 | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
ghsa5.5MEDIUM
osv5.5MEDIUM
vendor_debian5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
User login denial of service in github.com/google/fscrypt
osv·2024-08-21
CVE-2022-25327 User login denial of service in github.com/google/fscrypt
User login denial of service in github.com/google/fscrypt
User login denial of service in github.com/google/fscrypt
OSV
Denial of service via insufficient metadata validation
osv·2022-03-01·CVSS 5.5
CVE-2022-25327 [MEDIUM] Denial of service via insufficient metadata validation
Denial of service via insufficient metadata validation
The PAM module for `fscrypt` through v0.3.2 doesn't adequately validate `fscrypt` metadata files, allowing users to create malicious metadata files that prevent other users from logging in. A local user can cause a denial of service by creating a `fscrypt` metadata file that prevents other users from logging into the system. We recommend upgrading to v0.3.3 or above.
For more details, see [CVE-2022-25327](https://www.cve.org/CVERecord?id=CVE-2022-25327).
GHSA
Denial of service via insufficient metadata validation
ghsa·2022-03-01·CVSS 5.5
CVE-2022-25327 [MEDIUM] Denial of service via insufficient metadata validation
Denial of service via insufficient metadata validation
The PAM module for `fscrypt` through v0.3.2 doesn't adequately validate `fscrypt` metadata files, allowing users to create malicious metadata files that prevent other users from logging in. A local user can cause a denial of service by creating a `fscrypt` metadata file that prevents other users from logging into the system. We recommend upgrading to v0.3.3 or above.
For more details, see [CVE-2022-25327](https://www.cve.org/CVERecord?id=CVE-2022-25327).
GHSA
User login denial of service in github.com/google/fscrypt
ghsa·2022-02-26
CVE-2022-25327 [MEDIUM] CWE-276 User login denial of service in github.com/google/fscrypt
User login denial of service in github.com/google/fscrypt
The PAM module for fscrypt doesn't adequately validate fscrypt metadata files, allowing users to create malicious metadata files that prevent other users from logging in. A local user can cause a denial of service by creating a fscrypt metadata file that prevents other users from logging into the system. We recommend upgrading to version 0.3.3 or above
OSV
User login denial of service in github.com/google/fscrypt
osv·2022-02-26
CVE-2022-25327 [MEDIUM] User login denial of service in github.com/google/fscrypt
User login denial of service in github.com/google/fscrypt
The PAM module for fscrypt doesn't adequately validate fscrypt metadata files, allowing users to create malicious metadata files that prevent other users from logging in. A local user can cause a denial of service by creating a fscrypt metadata file that prevents other users from logging into the system. We recommend upgrading to version 0.3.3 or above
OSV
CVE-2022-25327: The PAM module for fscrypt doesn't adequately validate fscrypt metadata files, allowing users to create malicious metadata files that prevent other us
osv·2022-02-25·CVSS 5.5
CVE-2022-25327 [MEDIUM] CVE-2022-25327: The PAM module for fscrypt doesn't adequately validate fscrypt metadata files, allowing users to create malicious metadata files that prevent other us
The PAM module for fscrypt doesn't adequately validate fscrypt metadata files, allowing users to create malicious metadata files that prevent other users from logging in. A local user can cause a denial of service by creating a fscrypt metadata file that prevents other users from logging into the system. We recommend upgrading to version 0.3.3 or above
Debian
CVE-2022-25327: fscrypt - The PAM module for fscrypt doesn't adequately validate fscrypt metadata files, a...
vendor_debian·2022·CVSS 5.5
CVE-2022-25327 [MEDIUM] CVE-2022-25327: fscrypt - The PAM module for fscrypt doesn't adequately validate fscrypt metadata files, a...
The PAM module for fscrypt doesn't adequately validate fscrypt metadata files, allowing users to create malicious metadata files that prevent other users from logging in. A local user can cause a denial of service by creating a fscrypt metadata file that prevents other users from logging into the system. We recommend upgrading to version 0.3.3 or above
Scope: local
bookworm: resolved (fixed in 0.3.3-1)
bullseye: open
forky: resolved (fixed in 0.3.3-1)
sid: resolved (fixed in 0.3.3-1)
trixie: resolved (fixed in 0.3.3-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-02-25
Published