VDB
Sign up
MEDIUM

GHSA-w4f8-fxq2-j35v

Possible privilege escalation via bash completion script

Quick fix

GHSA-w4f8-fxq2-j35v — github.com/google/fscrypt: upgrade to the fixed version with the command below.

go get github.com/google/fscrypt@v0.3.3

Details

The bash completion script for `fscrypt` through v0.3.2 allows injection of commands via crafted mountpoint paths, allowing privilege escalation under a specific set of circumstances. A local user who has control over mountpoint paths could potentially escalate their privileges if they create a malicious mountpoint path and if the system administrator happens to be using the `fscrypt` bash completion script to complete mountpoint paths. We recommend upgrading to v0.3.3 or above.

For more details, see [CVE-2022-25328](https://www.cve.org/CVERecord?id=CVE-2022-25328).

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/google/fscrypt
Introduced in: 0Fixed in: 0.3.3
Fixgo get github.com/google/fscrypt@v0.3.3

References