Medium severity5.5NVD Advisory· Published Feb 25, 2022· Updated Jun 17, 2026
CVE-2022-25327
CVE-2022-25327
Description
The PAM module for fscrypt doesn't adequately validate fscrypt metadata files, allowing users to create malicious metadata files that prevent other users from logging in. A local user can cause a denial of service by creating a fscrypt metadata file that prevents other users from logging into the system. We recommend upgrading to version 0.3.3 or above
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/google/fscryptGo | < 0.3.3 | 0.3.3 |
Affected products
4- ghsa-coords2 versions
< 0.3.3+ 1 more
- (no CPE)range: < 0.3.3
- (no CPE)range: < 0.3.3-1.1
- Google LLC/fscryptv5Range: unspecified
Patches
Vulnerability mechanics
References
4- github.com/google/fscrypt/pull/346nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-8vwm-8vj8-rqjfghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-25327ghsaADVISORY
- github.com/google/fscrypt/commit/91aa3ebf42032ca783c41f9ec25d885875f66ddbghsaWEB
News mentions
0No linked articles in our index yet.