libseccomp before 2.4.0 did not correctly generate 64-bit syscall argument comparisons using the arithmetic operators (LT, GT, LE, GE), which might able to lead to bypassing seccomp filters and potential privilege escalations.
{ "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "2.4.1-0ubuntu0.14.04.2", "binary_name": "libseccomp-dev" }, { "binary_version": "2.4.1-0ubuntu0.14.04.2", "binary_name": "libseccomp2" }, { "binary_version": "2.4.1-0ubuntu0.14.04.2", "binary_name": "libseccomp2-dbgsym" }, { "binary_version": "2.4.1-0ubuntu0.14.04.2", "binary_name": "seccomp" }, { "binary_version": "2.4.1-0ubuntu0.14.04.2", "binary_name": "seccomp-dbgsym" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "2.4.1-0ubuntu0.16.04.2", "binary_name": "libseccomp-dev" }, { "binary_version": "2.4.1-0ubuntu0.16.04.2", "binary_name": "libseccomp2" }, { "binary_version": "2.4.1-0ubuntu0.16.04.2", "binary_name": "libseccomp2-dbgsym" }, { "binary_version": "2.4.1-0ubuntu0.16.04.2", "binary_name": "seccomp" }, { "binary_version": "2.4.1-0ubuntu0.16.04.2", "binary_name": "seccomp-dbgsym" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "2.4.1-0ubuntu0.18.04.2", "binary_name": "libseccomp-dev" }, { "binary_version": "2.4.1-0ubuntu0.18.04.2", "binary_name": "libseccomp2" }, { "binary_version": "2.4.1-0ubuntu0.18.04.2", "binary_name": "libseccomp2-dbgsym" }, { "binary_version": "2.4.1-0ubuntu0.18.04.2", "binary_name": "seccomp" }, { "binary_version": "2.4.1-0ubuntu0.18.04.2", "binary_name": "seccomp-dbgsym" } ] }