The pam_fscrypt module in fscrypt before 0.2.4 may incorrectly restore primary and supplementary group IDs to the values associated with the root user, which allows attackers to gain privileges via a successful login through certain applications that use Linux-PAM (aka pam).
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "0.2.2-0ubuntu2.1", "binary_name": "fscrypt" }, { "binary_version": "0.2.2-0ubuntu2.1", "binary_name": "golang-github-google-fscrypt-dev" }, { "binary_version": "0.2.2-0ubuntu2.1", "binary_name": "libpam-fscrypt" } ] }