Lucene search

K
osvGoogleOSV:USN-4574-1
HistoryOct 07, 2020 - 7:32 p.m.

golang-github-seccomp-libseccomp-golang vulnerability

2020-10-0719:32:20
Google
osv.dev
15
vulnerability
seccomp filter
syscall arguments

AI Score

7.1

Confidence

Low

EPSS

0.003

Percentile

70.0%

It was discovered that libseccomp-golang did not properly generate BPFs. If
a process were running under a restrictive seccomp filter that specified
multiple syscall arguments, the application could potentially bypass the
intended restrictions put in place by seccomp.