Skip to content

x/vulndb: potential Go vuln in github.com/google/fscrypt: CVE-2022-25328 #248

Open
@jba

Description

@jba

In CVE-2022-25328, the reference URL github.com/google/fscrypt (and possibly others) refers to something in Go.

module: github.com/google/fscrypt
package: fscrypt
description: |
    The bash_completion script for fscrypt allows injection of commands via crafted mountpoint paths, allowing privilege escalation under a specific set of circumstances. A local user who has control over mountpoint paths could potentially escalate their privileges if they create a malicious mountpoint path and if the system administrator happens to be using the fscrypt bash completion script to complete mountpoint paths.  We recommend upgrading to version 0.3.3 or above
cves:
  - CVE-2022-25328
credit: Matthias Gerstner of SUSE
links:
    pr: https://github.com/google/fscrypt/pull/346

See doc/triage.md for instructions on how to triage this report.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions