{"id":"GHSA-p93v-m2r2-4387","summary":"Denial of service via insufficient metadata validation","details":"The PAM module for `fscrypt` through v0.3.2 doesn't adequately validate `fscrypt` metadata files, allowing users to create malicious metadata files that prevent other users from logging in. A local user can cause a denial of service by creating a `fscrypt` metadata file that prevents other users from logging into the system. We recommend upgrading to v0.3.3 or above.\n\nFor more details, see [CVE-2022-25327](https://www.cve.org/CVERecord?id=CVE-2022-25327).","aliases":["CVE-2022-25327","GHSA-8vwm-8vj8-rqjf","GO-2022-0340"],"modified":"2026-06-08T16:15:09.905787372Z","published":"2022-03-01T21:05:01Z","database_specific":{"github_reviewed_at":"2022-03-01T21:05:01Z","nvd_published_at":null,"cwe_ids":[],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/google/fscrypt/security/advisories/GHSA-p93v-m2r2-4387"},{"type":"WEB","url":"https://github.com/google/fscrypt/commit/91aa3ebf42032ca783c41f9ec25d885875f66ddb"},{"type":"WEB","url":"https://pkg.go.dev/vuln/GO-2022-0340"},{"type":"PACKAGE","url":"github.com/google/fscrypt"}],"affected":[{"package":{"name":"github.com/google/fscrypt","ecosystem":"Go","purl":"pkg:golang/github.com/google/fscrypt"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.3.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/03/GHSA-p93v-m2r2-4387/GHSA-p93v-m2r2-4387.json"}}],"schema_version":"1.9.0"}