fscrypt through v0.3.2 creates a world-writable directory by default when setting up a filesystem, allowing unprivileged users to exhaust filesystem space. We recommend upgrading to fscrypt 0.3.3 or above and adjusting the permissions on existing fscrypt metadata directories where applicable.
References
Link | Resource |
---|---|
https://github.com/google/fscrypt/pull/346 | Patch Third Party Advisory |
Configurations
Information
Published : 2022-02-25 03:15
Updated : 2022-03-04 13:22
NVD link : CVE-2022-25326
Mitre link : CVE-2022-25326
JSON object : View
CWE
CWE-400
Uncontrolled Resource Consumption
Products Affected
- fscrypt