VDB
Sign up
MEDIUM4.8

GHSA-58v3-j75h-xr49

Improper Input Validation in libseccomp-golang

Quick fix

GHSA-58v3-j75h-xr49 — github.com/seccomp/libseccomp-golang: upgrade to the fixed version with the command below.

go get github.com/seccomp/libseccomp-golang@v0.9.1

Details

libseccomp-golang 0.9.0 and earlier incorrectly generates BPFs that OR multiple arguments rather than ANDing them. A process running under a restrictive seccomp filter that specified multiple syscall arguments could bypass intended access restrictions by specifying a single matching argument.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/seccomp/libseccomp-golang
Introduced in: 0Fixed in: 0.9.1
Fixgo get github.com/seccomp/libseccomp-golang@v0.9.1

References