Privilege escalation through command injection in fscrypt
Published Feb 25, 2022
7.3
HIGHCVSS 3.1
EPSS 0.20%
Description
The bash_completion script for fscrypt allows injection of commands via crafted mountpoint paths, allowing privilege escalation under a specific set of circumstances. A local user who has control over mountpoint paths could potentially escalate their privileges if they create a malicious mountpoint path and if the system administrator happens to be using the fscrypt bash completion script to complete mountpoint paths. We recommend upgrading to version 0.3.3 or above
Affected products
-
- Version unspecifiedStatusaffectedConstraints<=0.3.2
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Google LLC | Fscrypt | n/a |
|
No data.
No Red Hat product state for this CVE.
github.com/google/fscrypt
Go
Introduced 0 Fixed 0.3.3
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/google/fscrypt | 0 | 0.3.3 |
Remediation
No remediation recorded yet.
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-1242 Advisory
- https://github.com/advisories/GHSA-wxjg-p59j-6c92 Advisory
- https://github.com/google/fscrypt/pull/346 x_refsource_MISCPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-25328
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-1242 | Advisory | |
| https://github.com/advisories/GHSA-wxjg-p59j-6c92 | Advisory | |
| https://github.com/google/fscrypt/pull/346 | x_refsource_MISCPatchThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-25328 |
Change history (0)
No recorded changes yet.