The pam_fscrypt module in fscrypt before 0.2.4 may incorrectly restore primary and supplementary group IDs to the values associated with the root user, which allows attackers to gain privileges via a successful login through certain applications that use Linux-PAM (aka pam).
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "fscrypt",
"binary_version": "0.2.2-0ubuntu2.1"
},
{
"binary_name": "golang-github-google-fscrypt-dev",
"binary_version": "0.2.2-0ubuntu2.1"
},
{
"binary_name": "libpam-fscrypt",
"binary_version": "0.2.2-0ubuntu2.1"
}
]
}