← Back

CVE-2022-25328

nvd nist
Published: Feb 25, 2022Modified: Nov 21, 2024

JSON object

Loading...
7.3
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.3 / Impact: 5.9
Source: NVD

Description

The bash_completion script for fscrypt allows injection of commands via crafted mountpoint paths, allowing privilege escalation under a specific set of circumstances. A local user who has control over mountpoint paths could potentially escalate their privileges if they create a malicious mountpoint path and if the system administrator happens to be using the fscrypt bash completion script to complete mountpoint paths. We recommend upgrading to version 0.3.3 or above

Affected (1)

Products: Google: Fscrypt
1 product
Fscrypt
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 0.3.3

References (2)

Source: cve-coordination@google.com
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.