libseccomp-golang 0.9.0 and earlier incorrectly generates BPFs that OR multiple arguments rather than ANDing them. A process running under a restrictive seccomp filter that specified multiple syscall arguments could bypass intended access restrictions by specifying a single matching argument.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade golang-github-seccomp-libseccomp-golang | Aug 11, 2020 | Apr 24, 2019 |
| Redhat Openshift | — | Upgrade openshiftUpgrade atomic-openshift | Dec 18, 2019 | Apr 24, 2019 |
| Ubuntu | — | Upgrade golang-github-seccomp-libseccomp-golang-dev | Oct 8, 2020 | Apr 24, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub