GHSA-chxf-fjcf-7fwp
Dashboard / Vulnerabilities / GHSA-chxf-fjcf-7fwp
GHSA-chxf-fjcf-7fwp
Summary: Possible filesystem space exhaustion by local users
Details: `fscrypt` through v0.3.2 creates a world-writable directory by default when setting up a filesystem, allowing unprivileged users to exhaust filesystem space. We recommend upgrading to `fscrypt` v0.3.3 or above and adjusting the permissions on existing `fscrypt` metadata directories where applicable. For more details, see [CVE-2022-25326](https://www.cve.org/CVERecord?id=CVE-2022-25326) and https://github.com/google/fscrypt#setting-up-fscrypt-on-a-filesystem.
References: https://github.com/google/fscrypt/security/advisories/GHSA-chxf-fjcf-7fwp, https://github.com/google/fscrypt
Affected packages
Package
Name: github.com/google/fscrypt
Purl: pkg:golang/github.com/google/fscrypt
Affected ranges
Type: SEMVER
Events:
