Fscrypt
Vendor:
First CVE: Aug 23, 2018 · Active for 7 years
4
Total CVEs
More Total CVEs than 72% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
6.2
Avg CVSS
Higher Avg CVSS than 24% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Fscrypt over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 23, 2018
7 years ago
Most Recent CVE
Feb 25, 2022
1,610 days ago
CVE Severity & Scoring
Fscrypt4 CVEs
75%
25%
All CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local3 (75.0%)
Network1 (25.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (75.0%)
Unknown0 (0.0%)
Required1 (25.0%)
Privileges Required
Low4 (100.0%)
High0 (0.0%)
None0 (0.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-6558MEDIUM The pam_fscrypt module in fscrypt before 0.2.4 may incorrectly restore primary and supplementary group IDs to the values associated with the root user, which allows attackers to ga | Aug 23, 2018 | 6.5 | 22 | NO | NO |
CVE-2022-25327MEDIUM The PAM module for fscrypt doesn't adequately validate fscrypt metadata files, allowing users to create malicious metadata files that prevent other users from logging in. A local u | Feb 25, 2022 | 5.5 | 20 | NO | NO |
CVE-2022-25326MEDIUM fscrypt through v0.3.2 creates a world-writable directory by default when setting up a filesystem, allowing unprivileged users to exhaust filesystem space. We recommend upgrading t | Feb 25, 2022 | 5.5 | 20 | NO | NO |
CVE-2022-25328HIGH The bash_completion script for fscrypt allows injection of commands via crafted mountpoint paths, allowing privilege escalation under a specific set of circumstances. A local user | Feb 25, 2022 | 7.3 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (4 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (4 CVEs).
Media Mentions
Signals from CVEs in this product scope (4 CVEs).
Top CNAs Publishing CVEs For Fscrypt
Top CWEs
Versions
No cataloged versions.