Medium severity6.5NVD Advisory· Published Aug 23, 2018· Updated Jun 17, 2026
CVE-2018-6558
CVE-2018-6558
Description
The pam_fscrypt module in fscrypt before 0.2.4 may incorrectly restore primary and supplementary group IDs to the values associated with the root user, which allows attackers to gain privileges via a successful login through certain applications that use Linux-PAM (aka pam).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/google/fscryptGo | < 0.2.4 | 0.2.4 |
Affected products
3- Range: before 0.2.4
Patches
Vulnerability mechanics
References
7- github.com/google/fscrypt/commit/3022c1603d968c22f147b4a2c49c4637dd1be91bnvdPatchThird Party AdvisoryWEB
- github.com/google/fscrypt/commit/315f9b042237200174a1fb99427f74027e191d66nvdPatchThird Party AdvisoryWEB
- launchpad.net/bugs/1787548nvdIssue TrackingPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-qj26-7grj-whg3ghsaADVISORY
- github.com/google/fscrypt/issues/77nvdIssue TrackingThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2018-6558ghsaADVISORY
- pkg.go.dev/vuln/GO-2020-0027ghsaWEB
News mentions
0No linked articles in our index yet.