5.5
CVSSv3

CVE-2022-25326

Published: 25/02/2022 Updated: 04/03/2022
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

fscrypt through v0.3.2 creates a world-writable directory by default when setting up a filesystem, allowing unprivileged users to exhaust filesystem space. We recommend upgrading to fscrypt 0.3.3 or above and adjusting the permissions on existing fscrypt metadata directories where applicable.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

google fscrypt

Vendor Advisories

Debian Bug report logs - #1006485 fscrypt: CVE-2022-25326 CVE-2022-25327 CVE-2022-25328 Package: src:fscrypt; Maintainer for src:fscrypt is Debian Go Packaging Team <team+pkg-go@trackerdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 26 Feb 2022 09:36:02 UTC Severity: grave Tags: securit ...