CVE-2017-18367

Source
https://nvd.nist.gov/vuln/detail/CVE-2017-18367
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-18367.json
Aliases
Related
Published
2019-04-24T21:29:00Z
Modified
2023-11-29T06:11:10.941969Z
Details

libseccomp-golang 0.9.0 and earlier incorrectly generates BPFs that OR multiple arguments rather than ANDing them. A process running under a restrictive seccomp filter that specified multiple syscall arguments could bypass intended access restrictions by specifying a single matching argument.

References

Affected packages

Git / github.com/seccomp/libseccomp-golang

Affected ranges

Type
GIT
Repo
https://github.com/seccomp/libseccomp-golang
Events
Introduced
0The exact introduced commit is unknown
Fixed

Affected versions

v0.*

v0.9.0