The pam_fscrypt module in fscrypt before 0.2.4 may incorrectly restore primary and supplementary group IDs to the values associated with the root user, which allows attackers to gain privileges via a successful login through certain applications that use Linux-PAM (aka pam)
Published Aug 23, 2018
6.5
MEDIUMCVSS 3.0
EPSS 0.62%
Description
The pam_fscrypt module in fscrypt before 0.2.4 may incorrectly restore primary and supplementary group IDs to the values associated with the root user, which allows attackers to gain privileges via a successful login through certain applications that use Linux-PAM (aka pam).
Affected products
-
- Version before 0.2.4StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| The fscrypt Project | Fscrypt | n/a |
|
No data.
No Red Hat product state for this CVE.
github.com/google/fscrypt
Go
Introduced 0 Fixed 0.2.4
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/google/fscrypt | 0 | 0.2.4 |
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
AV:N/AC:M/Au:S/C:N/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Table of values (10 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.62% (0.00624) | 47.97th | v5 (v2026.06.15) |
| Sep 20, 2026 | 0.62% (0.00624) | 48.50th | v5 (v2026.06.15) |
| Jul 20, 2024 | 0.11% (0.00108) | 44.24th | v3 (v2023.03.01) |
| Jan 14, 2024 | 0.11% (0.00108) | 43.39th | v3 (v2023.03.01) |
| Sep 3, 2023 | 0.10% (0.00095) | 39.42th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.09% (0.00086) | 34.84th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.95% (0.00950) | 32.28th | v2 (v2022.01.01) |
| Feb 4, 2022 | 0.95% (0.00950) | 13.46th | v2 (v2022.01.01) |
| Feb 3, 2022 | 0.43% (0.00430) | 10.10th | v5 (v2026.06.15) |
| Apr 14, 2021 | 0.43% (0.00430) | 0.00th | v1 |
No CWE recorded.
References (7)
- https://github.com/advisories/GHSA-qj26-7grj-whg3 Advisory
- https://github.com/google/fscrypt/commit/3022c1603d968c22f147b4a2c49c4637dd1be91b x_refsource_MISCPatchThird Party Advisory
- https://github.com/google/fscrypt/commit/315f9b042237200174a1fb99427f74027e191d66 x_refsource_MISCPatchThird Party Advisory
- https://github.com/google/fscrypt/issues/77 x_refsource_MISCIssue TrackingThird Party Advisory
- https://launchpad.net/bugs/1787548 x_refsource_MISCIssue TrackingPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-6558
- https://pkg.go.dev/vuln/GO-2020-0027
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-qj26-7grj-whg3 | Advisory | |
| https://github.com/google/fscrypt/commit/3022c1603d968c22f147b4a2c49c4637dd1be91b | x_refsource_MISCPatchThird Party Advisory | |
| https://github.com/google/fscrypt/commit/315f9b042237200174a1fb99427f74027e191d66 | x_refsource_MISCPatchThird Party Advisory | |
| https://github.com/google/fscrypt/issues/77 | x_refsource_MISCIssue TrackingThird Party Advisory | |
| https://launchpad.net/bugs/1787548 | x_refsource_MISCIssue TrackingPatchThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-6558 | ||
| https://pkg.go.dev/vuln/GO-2020-0027 |
Change history (0)
No recorded changes yet.