VDB

CVE-2022-25327

CVE-2022-25327 PUBLISHED CVSS 5.5 MEDIUM

The PAM module for fscrypt doesn't adequately validate fscrypt metadata files, allowing users to create malicious metadata files that prevent other users from logging in. A local user can cause a denial of service by creating a fscrypt metadata file that prevents other users from logging into the system. We recommend upgrading to version 0.3.3 or above

EPSS 0.11% · 1.6th percentile

Risk Scores

CVSS 3.1
5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Score
0.11%
1.6th percentile

Affected Products

VendorProductVersions
googlefscrypt0
Google LLCfscrypt*
github.comgoogle/fscrypt0

Timeline

  • Feb 25, 2022 CVE Published
  • Feb 26, 2022 EPSS Score
  • Apr 19, 2022 EPSS Score
  • Jun 10, 2022 EPSS Score
  • Aug 2, 2022 EPSS Score
  • Sep 22, 2022 EPSS Score
  • Nov 13, 2022 EPSS Score
  • Jan 4, 2023 EPSS Score
  • Feb 25, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 18, 2023 EPSS Score
  • Jun 9, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›