PT-2019-4976 · Seccomp+7 · Libseccomp+7

Jann Horn

·

Published

2019-03-14

·

Updated

2024-06-15

·

CVE-2019-9893

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions libseccomp versions prior to 2.4.0
Description The issue is related to the incorrect generation of 64-bit syscall argument comparisons using arithmetic operators, which might allow bypassing seccomp filters and potential privilege escalations. The vulnerability is associated with insufficient access control to certain functions, potentially enabling a remote attacker to access confidential data, compromise its integrity, and cause a denial of service.
Recommendations For versions prior to 2.4.0, update to version 2.4.0 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1495
BDU:2020-01597
CESA-2019_3624
CVE-2019-9893
MGASA-2020-0136
OPENSUSE-SU-2019:2280-1
OPENSUSE-SU-2019:2283-1
OPENSUSE-SU-2019_2280-1
OPENSUSE-SU-2019_2283-1
OPENSUSE-SU-2024:10989-1
RHSA-2019:3624
RHSA-2019_3624
SUSE-SU-2019:2517-1
SUSE-SU-2019:2941-1
SUSE-SU-2019_2517-1
SUSE-SU-2019_2941-1
USN-4001-1
USN-4001-2

Affected Products

Alt Linux
Astra Linux
Centos
Red Hat
Red Os
Suse
Ubuntu
Libseccomp