PT-2026-39434 · Go · Github.Com/Tinfoil-Factory/Netfoil
Published
2026-04-29
·
Updated
2026-04-29
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Summary
The optional flag
--filter-system-calls was not applied even if specified.Details
This is a defense in depth feature to apply additional seccomp filters after the binary has started. The example config also sandboxes the binary with systemd.
Impact
Reduced sandboxing of the netfoil binary.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Github.Com/Tinfoil-Factory/Netfoil