Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Mageia 7 MGASA-2020-0136 Moderate: Libseccomp Access Restrictions Bypass

mageia
Calendar Grey March 10, 2020
Dist Mageia Esm H88
Recent updates to libseccomp packages deliver essential security improvements for Mageia users. Review the specifics regarding access restrictions.
Updated libseccomp packages fix security vulnerability: Jann Horn discovered that libseccomp did not correctly generate 64-bit syscall argument comparisons with arithmetic operato...

Summary

Updated libseccomp packages fix security vulnerability:
Jann Horn discovered that libseccomp did not correctly generate 64-bit syscall argument comparisons with arithmetic operators (LT, GT, LE, GE). An attacker could use this to bypass intended access restrictions for argument-filtered system calls (CVE-2019-9893).

References

- https://bugs.mageia.org/show_bug.cgi?id=24523

- https://ubuntu.com/security/notices/USN-4001-1

- https://www.cve.org/CVERecord?id=CVE-2019-9893

Resolution

SRPMS

- 7/core/libseccomp-2.4.2-1.mga7

Publication date: 10 Mar 2020
URL: https://advisories.mageia.org/MGASA-2020-0136.html
Type: security
CVE: CVE-2019-9893

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here