QID 982573
QID 982573: Go (go) Security Update for github.com/seccomp/libseccomp-golang (GHSA-58v3-j75h-xr49)
libseccomp-golang 0.9.0 and earlier incorrectly generates BPFs that OR multiple arguments rather than ANDing them. A process running under a restrictive seccomp filter that specified multiple syscall arguments could bypass intended access restrictions by specifying a single matching argument.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-58v3-j75h-xr49 for updates pertaining to this vulnerability.
Vendor References
- GHSA-58v3-j75h-xr49 -
github.com/advisories/GHSA-58v3-j75h-xr49
CVEs related to QID 982573
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-58v3-j75h-xr49 | github.com/seccomp/libseccomp-golang |
|