CVE Vulnerabilities

CVE-2019-9893

Published: Mar 21, 2019 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
7.3 MODERATE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

libseccomp before 2.4.0 did not correctly generate 64-bit syscall argument comparisons using the arithmetic operators (LT, GT, LE, GE), which might able to lead to bypassing seccomp filters and potential privilege escalations.

Affected Software

NameVendorStart VersionEnd Version
LibseccompLibseccomp_project*2.4.0 (excluding)
Red Hat Enterprise Linux 8RedHatlibseccomp-0:2.4.1-1.el8*
Red Hat Enterprise Linux 8RedHatlibseccomp-0:2.4.1-1.el8*
LibseccompUbuntubionic*
LibseccompUbuntucosmic*
LibseccompUbuntudevel*
LibseccompUbuntudisco*
LibseccompUbuntuesm-infra-legacy/trusty*
LibseccompUbuntuesm-infra/bionic*
LibseccompUbuntuesm-infra/xenial*
LibseccompUbuntutrusty*
LibseccompUbuntutrusty/esm*
LibseccompUbuntuupstream*
LibseccompUbuntuxenial*

References