CVE-2022-25326

Severity CVSS v4.0:
Pending analysis
Type:
CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
25/02/2022
Last modified:
04/03/2022

Description

fscrypt through v0.3.2 creates a world-writable directory by default when setting up a filesystem, allowing unprivileged users to exhaust filesystem space. We recommend upgrading to fscrypt 0.3.3 or above and adjusting the permissions on existing fscrypt metadata directories where applicable.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:google:fscrypt:*:*:*:*:*:*:*:* 0.3.2 (including)


References to Advisories, Solutions, and Tools