CVE-2022-25328
published 2022-02-25CVE-2022-25328: The bash_completion script for fscrypt allows injection of commands via crafted mountpoint paths, allowing privilege escalation under a specific set of…
PriorityP335high7.3CVSS 3.1
AVLACLPRLUIRSUCHIHAH
EPSS
0.20%
9.9th percentile
The bash_completion script for fscrypt allows injection of commands via crafted mountpoint paths, allowing privilege escalation under a specific set of circumstances. A local user who has control over mountpoint paths could potentially escalate their privileges if they create a malicious mountpoint path and if the system administrator happens to be using the fscrypt bash completion script to complete mountpoint paths. We recommend upgrading to version 0.3.3 or above
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | fscrypt | < fscrypt 0.3.3-1 (bookworm) | fscrypt 0.3.3-1 (bookworm) |
| github.com | google_fscrypt | >= 0 < 0.3.3 | 0.3.3 |
| fscrypt | < 0.3.3 | 0.3.3 | |
| fscrypt | >= 0 < 0.3.3-1 | 0.3.3-1 | |
| fscrypt | >= 0 < 0.3.3-1 | 0.3.3-1 | |
| fscrypt | >= 0 < 0.3.3-1 | 0.3.3-1 | |
| google_llc | fscrypt | unspecified – 0.3.2 | — |
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
ghsa7.3HIGH
osv7.3HIGH
vendor_debian5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Possible privilege escalation via bash completion script
osv·2022-03-01·CVSS 7.3
[HIGH] Possible privilege escalation via bash completion script
Possible privilege escalation via bash completion script
The bash completion script for `fscrypt` through v0.3.2 allows injection of commands via crafted mountpoint paths, allowing privilege escalation under a specific set of circumstances. A local user who has control over mountpoint paths could potentially escalate their privileges if they create a malicious mountpoint path and if the system administrator happens to be using the `fscrypt` bash completion script to complete mountpoint paths. We recommend upgrading to v0.3.3 or above.
For more details, see [CVE-2022-25328](https://www.cve.org/CVERecord?id=CVE-2022-25328).
GHSA
Possible privilege escalation via bash completion script
ghsa·2022-03-01·CVSS 7.3
[HIGH] Possible privilege escalation via bash completion script
Possible privilege escalation via bash completion script
The bash completion script for `fscrypt` through v0.3.2 allows injection of commands via crafted mountpoint paths, allowing privilege escalation under a specific set of circumstances. A local user who has control over mountpoint paths could potentially escalate their privileges if they create a malicious mountpoint path and if the system administrator happens to be using the `fscrypt` bash completion script to complete mountpoint paths. We recommend upgrading to v0.3.3 or above.
For more details, see [CVE-2022-25328](https://www.cve.org/CVERecord?id=CVE-2022-25328).
OSV
Command injection in github.com/google/fscrypt
osv·2022-02-26
CVE-2022-25328 [MEDIUM] Command injection in github.com/google/fscrypt
Command injection in github.com/google/fscrypt
The bash_completion script for fscrypt allows injection of commands via crafted mountpoint paths, allowing privilege escalation under a specific set of circumstances. A local user who has control over mountpoint paths could potentially escalate their privileges if they create a malicious mountpoint path and if the system administrator happens to be using the fscrypt bash completion script to complete mountpoint paths. We recommend upgrading to version 0.3.3 or above
GHSA
Command injection in github.com/google/fscrypt
ghsa·2022-02-26
CVE-2022-25328 [MEDIUM] CWE-78 Command injection in github.com/google/fscrypt
Command injection in github.com/google/fscrypt
The bash_completion script for fscrypt allows injection of commands via crafted mountpoint paths, allowing privilege escalation under a specific set of circumstances. A local user who has control over mountpoint paths could potentially escalate their privileges if they create a malicious mountpoint path and if the system administrator happens to be using the fscrypt bash completion script to complete mountpoint paths. We recommend upgrading to version 0.3.3 or above
OSV
CVE-2022-25328: The bash_completion script for fscrypt allows injection of commands via crafted mountpoint paths, allowing privilege escalation under a specific set o
osv·2022-02-25·CVSS 7.3
CVE-2022-25328 [HIGH] CVE-2022-25328: The bash_completion script for fscrypt allows injection of commands via crafted mountpoint paths, allowing privilege escalation under a specific set o
The bash_completion script for fscrypt allows injection of commands via crafted mountpoint paths, allowing privilege escalation under a specific set of circumstances. A local user who has control over mountpoint paths could potentially escalate their privileges if they create a malicious mountpoint path and if the system administrator happens to be using the fscrypt bash completion script to complete mountpoint paths. We recommend upgrading to version 0.3.3 or above
Debian
CVE-2022-25328: fscrypt - The bash_completion script for fscrypt allows injection of commands via crafted ...
vendor_debian·2022·CVSS 5.0
CVE-2022-25328 [MEDIUM] CVE-2022-25328: fscrypt - The bash_completion script for fscrypt allows injection of commands via crafted ...
The bash_completion script for fscrypt allows injection of commands via crafted mountpoint paths, allowing privilege escalation under a specific set of circumstances. A local user who has control over mountpoint paths could potentially escalate their privileges if they create a malicious mountpoint path and if the system administrator happens to be using the fscrypt bash completion script to complete mountpoint paths. We recommend upgrading to version 0.3.3 or above
Scope: local
bookworm: resolved (fixed in 0.3.3-1)
bullseye: open
forky: resolved (fixed in 0.3.3-1)
sid: resolved (fixed in 0.3.3-1)
trixie: resolved (fixed in 0.3.3-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-02-25
Published