libseccomp-golang 0.9.0 and earlier incorrectly generates BPFs that OR multiple arguments rather than ANDing them. A process running under a restrictive seccomp filter that specified multiple syscall arguments could bypass intended access restrictions by specifying a single matching argument.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| github.com/seccomp/libseccomp-golang(Go) | 0 | 0.9.1 | N/A |
CVSS Metrics