QID 982075
QID 982075: Go (go) Security Update for github.com/google/fscrypt/security (GHSA-qj26-7grj-whg3)
The pam_fscrypt module in fscrypt before 0.2.4 may incorrectly restore primary and supplementary group IDs to the values associated with the root user, which allows attackers to gain privileges via a successful login through certain applications that use Linux-PAM (aka pam).
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-qj26-7grj-whg3 for updates pertaining to this vulnerability.
Vendor References
- GHSA-qj26-7grj-whg3 -
github.com/advisories/GHSA-qj26-7grj-whg3
CVEs related to QID 982075
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-qj26-7grj-whg3 | github.com/google/fscrypt/security |
|