The PointerCompare function in codegen.cc in Seccomp-BPF, as used in Google Chrome before 34.0.1847.131 on Windows and OS X and before 34.0.1847.132 on Linux, does not properly merge blocks, which might allow remote attackers to bypass intended sandbox restrictions by leveraging renderer access.
{
"binaries": [
{
"binary_version": "36.0.1985.125-0ubuntu1.14.04.0~pkg1029",
"binary_name": "chromium-browser"
},
{
"binary_version": "36.0.1985.125-0ubuntu1.14.04.0~pkg1029",
"binary_name": "chromium-browser-l10n"
},
{
"binary_version": "36.0.1985.125-0ubuntu1.14.04.0~pkg1029",
"binary_name": "chromium-chromedriver"
},
{
"binary_version": "36.0.1985.125-0ubuntu1.14.04.0~pkg1029",
"binary_name": "chromium-codecs-ffmpeg"
},
{
"binary_version": "36.0.1985.125-0ubuntu1.14.04.0~pkg1029",
"binary_name": "chromium-codecs-ffmpeg-extra"
}
],
"availability": "No subscription required"
}