Description
The pam_fscrypt module in fscrypt before 0.2.4 may incorrectly restore primary and supplementary group IDs to the values associated with the root user, which allows attackers to gain privileges via a successful login through certain applications that use Linux-PAM (aka pam).
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-1381 | The pam_fscrypt module in fscrypt before 0.2.4 may incorrectly restore primary and supplementary group IDs to the values associated with the root user, which allows attackers to gain privileges via a successful login through certain applications that use Linux-PAM (aka pam). |
Github GHSA |
GHSA-qj26-7grj-whg3 | Privilege Escalation in fscrypt |
References
History
No history.
Status: PUBLISHED
Assigner: canonical
Published:
Updated: 2024-09-17T02:06:50.219Z
Reserved: 2018-02-02T00:00:00.000Z
Link: CVE-2018-6558
No data.
Status : Modified
Published: 2018-08-23T19:29:01.127
Modified: 2024-11-21T04:10:54.240
Link: CVE-2018-6558
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA