Security Advisory

CVE-2022-25328

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2022-02-25 11:00:15
Last updated 2025-04-21 13:56:13
Assigner Google
State PUBLISHED

Description

The bash_completion script for fscrypt allows injection of commands via crafted mountpoint paths, allowing privilege escalation under a specific set of circumstances. A local user who has control over mountpoint paths could potentially escalate their privileges if they create a malicious mountpoint path and if the system administrator happens to be using the fscrypt bash completion script to complete mountpoint paths. We recommend upgrading to version 0.3.3 or above