Privilege Escalation in fscrypt
Moderate severity
GitHub Reviewed
Published
Jun 23, 2021
to the GitHub Advisory Database
•
Updated May 20, 2024
Description
Reviewed
May 20, 2021
Published to the GitHub Advisory Database
Jun 23, 2021
Last updated
May 20, 2024
The pam_fscrypt module in fscrypt before 0.2.4 may incorrectly restore primary and supplementary group IDs to the values associated with the root user, which allows attackers to gain privileges via a successful login through certain applications that use Linux-PAM (aka pam).
References