The pam_fscrypt module in fscrypt before 0.2.4 may incorrectly restore primary and supplementary group IDs to the values associated with the root user, which allows attackers to gain privileges via a successful login through certain applications that use Linux-PAM (aka pam).
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_name": "fscrypt", "binary_version": "0.2.2-0ubuntu2.1" }, { "binary_name": "golang-github-google-fscrypt-dev", "binary_version": "0.2.2-0ubuntu2.1" }, { "binary_name": "libpam-fscrypt", "binary_version": "0.2.2-0ubuntu2.1" } ] }