Back

HIGH

Privilege escalation through command injection in fscrypt

Published Feb 25, 2022

Description

The bash_completion script for fscrypt allows injection of commands via crafted mountpoint paths, allowing privilege escalation under a specific set of circumstances. A local user who has control over mountpoint paths could potentially escalate their privileges if they create a malicious mountpoint path and if the system administrator happens to be using the fscrypt bash completion script to complete mountpoint paths. We recommend upgrading to version 0.3.3 or above

Affected products

Remediation

No remediation recorded yet.

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Google
Published Feb 25, 2022
Updated Apr 21, 2025
Reserved Feb 18, 2022
CISA Vulnrichment
Updated Apr 21, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner Google
Published Feb 25, 2022
Updated Apr 21, 2025
Exploited since n/a
EUVD-2022-1242 GHSA-WXJG-P59J-6C92