Medium severity5.5NVD Advisory· Published Feb 25, 2022· Updated Jun 17, 2026
CVE-2022-25326
CVE-2022-25326
Description
fscrypt through v0.3.2 creates a world-writable directory by default when setting up a filesystem, allowing unprivileged users to exhaust filesystem space. We recommend upgrading to fscrypt 0.3.3 or above and adjusting the permissions on existing fscrypt metadata directories where applicable.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/google/fscryptGo | < 0.3.3 | 0.3.3 |
Affected products
4- ghsa-coords2 versions
< 0.3.3+ 1 more
- (no CPE)range: < 0.3.3
- (no CPE)range: < 0.3.3-1.1
- Google LLC/fscryptv5Range: unspecified
Patches
Vulnerability mechanics
References
4- github.com/google/fscrypt/pull/346nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-mpq4-rjj8-fjphghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-25326ghsaADVISORY
- github.com/google/fscrypt/commit/91aa3ebf42032ca783c41f9ec25d885875f66ddbghsaWEB
News mentions
0No linked articles in our index yet.