CVE-2018-6558: Google Fscrypt
Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.
The pam_fscrypt module in fscrypt before 0.2.4 may incorrectly restore primary and supplementary group IDs to the values associated with the root user, which allows attackers to gain privileges via a successful login through certain applications that use Linux-PAM (aka pam).
Affected products
- Google Fscrypt: before 0.2.4 (fixed in 0.2.4)
Published 2018-08-23. Last modified 2026-06-17.