The pam_fscrypt module in fscrypt before 0.2.4 may incorrectly restore primary and supplementary group IDs to the values associated with the root user, which allows attackers to gain privileges via a successful login through certain applications that use Linux-PAM (aka pam).
{
"availability": "No subscription required",
"binaries": [
{
"binary_version": "0.2.2-0ubuntu2.1",
"binary_name": "fscrypt"
},
{
"binary_version": "0.2.2-0ubuntu2.1",
"binary_name": "golang-github-google-fscrypt-dev"
},
{
"binary_version": "0.2.2-0ubuntu2.1",
"binary_name": "libpam-fscrypt"
}
]
}