Possible filesystem space exhaustion by local users
Package
Affected versions
< 0.3.3
Patched versions
0.3.3
Description
Published to the GitHub Advisory Database
Mar 1, 2022
Reviewed
Mar 1, 2022
Last updated
Jan 11, 2023
fscrypt
through v0.3.2 creates a world-writable directory by default when setting up a filesystem, allowing unprivileged users to exhaust filesystem space. We recommend upgrading tofscrypt
v0.3.3 or above and adjusting the permissions on existingfscrypt
metadata directories where applicable.For more details, see CVE-2022-25326 and https://github.com/google/fscrypt#setting-up-fscrypt-on-a-filesystem.
References