CVE Vulnerabilities

CVE-2019-9893

Published: Mar 21, 2019 | Modified: Aug 24, 2020
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
7.3 MODERATE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Ubuntu
MEDIUM

libseccomp before 2.4.0 did not correctly generate 64-bit syscall argument comparisons using the arithmetic operators (LT, GT, LE, GE), which might able to lead to bypassing seccomp filters and potential privilege escalations.

Affected Software

Name Vendor Start Version End Version
Libseccomp Libseccomp_project * 2.4.0 (excluding)
Red Hat Enterprise Linux 8 RedHat libseccomp-0:2.4.1-1.el8 *
Red Hat Enterprise Linux 8 RedHat libseccomp-0:2.4.1-1.el8 *
Libseccomp Ubuntu bionic *
Libseccomp Ubuntu cosmic *
Libseccomp Ubuntu devel *
Libseccomp Ubuntu disco *
Libseccomp Ubuntu trusty *
Libseccomp Ubuntu trusty/esm *
Libseccomp Ubuntu upstream *
Libseccomp Ubuntu xenial *

References