CVE Published: 23/08/2018 |
CVE Updated: 17/09/2024 |
CVE Year: 2018 Source: canonical |
Vendor: The fscrypt Project |
Product: fscrypt Status : PUBLISHED
CVE-2018-6558 Description
The pam_fscrypt module in fscrypt before 0.2.4 may incorrectly restore primary and supplementary group IDs to the values associated with the root user, which allows attackers to gain privileges via a successful login through certain applications that use Linux-PAM (aka pam).