VDB
CVE-2022-25327
CVE-2022-25327
PUBLISHED
CVSS 5.5 MEDIUM
The PAM module for fscrypt doesn't adequately validate fscrypt metadata files, allowing users to create malicious metadata files that prevent other users from logging in. A local user can cause a denial of service by creating a fscrypt metadata file that prevents other users from logging into the system. We recommend upgrading to version 0.3.3 or above
EPSS 0.11% · 1.6th percentile
Risk Scores
CVSS 3.1
5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Score
0.11%
1.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| fscrypt | 0 | |
| Google LLC | fscrypt | * |
| github.com | google/fscrypt | 0 |
Timeline
- Feb 25, 2022 CVE Published
- Feb 26, 2022 EPSS Score
- Apr 19, 2022 EPSS Score
- Jun 10, 2022 EPSS Score
- Aug 2, 2022 EPSS Score
- Sep 22, 2022 EPSS Score
- Nov 13, 2022 EPSS Score
- Jan 4, 2023 EPSS Score
- Feb 25, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 18, 2023 EPSS Score
- Jun 9, 2023 EPSS Score