VDB

RHSA-2019%3A4090

RHSA-2019%3A4090 PUBLISHED CVSS 6.5 MEDIUM

libseccomp-golang 0.9.0 and earlier incorrectly generates BPFs that OR multiple arguments rather than ANDing them. A process running under a restrictive seccomp filter that specified multiple syscall arguments could bypass intended access restrictions by specifying a single matching argument.

Risk Scores

CVSS 3.0
6.5
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Affected Products

VendorProductVersions
Red Hatopenshift4/ose-hypershift@sha256:9d3082a8a1d089b14adc69f8ade5f8c776938d9dd9d7cfe163b757bb1e67f8e4_amd64 as a component of Red Hat OpenShift Container Platform 4.1openshift4/ose-hypershift@sha256:9d3082a8a1d089b14adc69f8ade5f8c776938d9dd9d7cfe163b757bb1e67f8e4_amd64
Red Hatopenshift4/ose-hyperkube@sha256:c5fa17f9a2bb8ba2f99f71004d49f2987474379848ebc4ec8c47c414973ccc2a_amd64 as a component of Red Hat OpenShift Container Platform 4.1openshift4/ose-hyperkube@sha256:c5fa17f9a2bb8ba2f99f71004d49f2987474379848ebc4ec8c47c414973ccc2a_amd64
Red Hatopenshift4/ose-cli-artifacts@sha256:924e58fc7b0fee286cc33cf675c7bb4746df56ac1307102f5c196b67caf2de18_amd64 as a component of Red Hat OpenShift Container Platform 4.1openshift4/ose-cli-artifacts@sha256:924e58fc7b0fee286cc33cf675c7bb4746df56ac1307102f5c196b67caf2de18_amd64
Red Hatopenshift4/ose-cli@sha256:33af908590a01d4f8f0e06c99f46fb5a861cb6e8b9176b6f40d0198ca1668005_amd64 as a component of Red Hat OpenShift Container Platform 4.1openshift4/ose-cli@sha256:33af908590a01d4f8f0e06c99f46fb5a861cb6e8b9176b6f40d0198ca1668005_amd64

Timeline

  • Dec 17, 2019 CVE Published
  • Feb 27, 2026 CVE Updated
  • Apr 30, 2026 Distribution Patch
  • Apr 30, 2026 Distribution Patch
  • Apr 30, 2026 Security Advisory
  • Apr 30, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›