CVE-2018-6558: Google Fscrypt

Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.

The pam_fscrypt module in fscrypt before 0.2.4 may incorrectly restore primary and supplementary group IDs to the values associated with the root user, which allows attackers to gain privileges via a successful login through certain applications that use Linux-PAM (aka pam).

Affected products

  • Google Fscrypt: before 0.2.4 (fixed in 0.2.4)

Published 2018-08-23. Last modified 2026-06-17.