{"id":"GHSA-chxf-fjcf-7fwp","summary":"Possible filesystem space exhaustion by local users","details":"`fscrypt` through v0.3.2 creates a world-writable directory by default when setting up a filesystem, allowing unprivileged users to exhaust filesystem space. We recommend upgrading to `fscrypt` v0.3.3 or above and adjusting the permissions on existing `fscrypt` metadata directories where applicable.\n\nFor more details, see [CVE-2022-25326](https://www.cve.org/CVERecord?id=CVE-2022-25326) and https://github.com/google/fscrypt#setting-up-fscrypt-on-a-filesystem.\n","aliases":["CVE-2022-25326","GHSA-mpq4-rjj8-fjph","GO-2022-0339"],"modified":"2024-08-21T14:57:29.703509Z","published":"2022-03-01T21:04:07Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2022-03-01T21:04:07Z","nvd_published_at":null,"cwe_ids":[]},"references":[{"type":"WEB","url":"https://github.com/google/fscrypt/security/advisories/GHSA-chxf-fjcf-7fwp"},{"type":"PACKAGE","url":"https://github.com/google/fscrypt"}],"affected":[{"package":{"name":"github.com/google/fscrypt","ecosystem":"Go","purl":"pkg:golang/github.com/google/fscrypt"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.3.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/03/GHSA-chxf-fjcf-7fwp/GHSA-chxf-fjcf-7fwp.json"}}],"schema_version":"1.9.0"}