Описание
Security update for libseccomp
This update for libseccomp fixes the following issues:
Update to new upstream release 2.4.1:
- Fix a BPF generation bug where the optimizer mistakenly identified duplicate BPF code blocks.
Updated to 2.4.0 (bsc#1128828 CVE-2019-9893):
- Update the syscall table for Linux v5.0-rc5
- Added support for the SCMP_ACT_KILL_PROCESS action
- Added support for the SCMP_ACT_LOG action and SCMP_FLTATR_CTL_LOG attribute
- Added explicit 32-bit (SCMP_AX_32(...)) and 64-bit (SCMP_AX_64(...)) argument comparison macros to help protect against unexpected sign extension
- Added support for the parisc and parisc64 architectures
- Added the ability to query and set the libseccomp API level via seccomp_api_get(3) and seccomp_api_set(3)
- Return -EDOM on an endian mismatch when adding an architecture to a filter
- Renumber the pseudo syscall number for subpage_prot() so it no longer conflicts with spu_run()
- Fix PFC generation when a syscall is prioritized, but no rule exists
- Numerous fixes to the seccomp-bpf filter generation code
- Switch our internal hashing function to jhash/Lookup3 to MurmurHash3
- Numerous tests added to the included test suite, coverage now at ~92%
- Update our Travis CI configuration to use Ubuntu 16.04
- Numerous documentation fixes and updates
Update to release 2.3.3:
- Updated the syscall table for Linux v4.15-rc7
Update to release 2.3.2:
- Achieved full compliance with the CII Best Practices program
- Added Travis CI builds to the GitHub repository
- Added code coverage reporting with the '--enable-code-coverage' configure flag and added Coveralls to the GitHub repository
- Updated the syscall tables to match Linux v4.10-rc6+
- Support for building with Python v3.x
- Allow rules with the -1 syscall if the SCMP_FLTATR_API_TSKIP attribute is set to true
- Several small documentation fixes
- ignore make check error for ppc64/ppc64le, bypass bsc#1142614
Список пакетов
Container caasp/v4/nginx-ingress-controller:beta1
libseccomp2-2.4.1-11.3.2
Container suse/sles12sp3:latest
libseccomp2-2.4.1-11.3.2
HPE Helion OpenStack 8
libseccomp2-2.4.1-11.3.2
libseccomp2-32bit-2.4.1-11.3.2
Image SLES12-SP4-Azure-BYOS
libseccomp2-2.4.1-11.3.2
Image SLES12-SP4-EC2-HVM-BYOS
libseccomp2-2.4.1-11.3.2
Image SLES12-SP4-GCE-BYOS
libseccomp2-2.4.1-11.3.2
Image SLES12-SP4-OCI-BYOS
libseccomp2-2.4.1-11.3.2
Image SLES12-SP4-SAP-Azure
libseccomp2-2.4.1-11.3.2
Image SLES12-SP4-SAP-Azure-BYOS
libseccomp2-2.4.1-11.3.2
Image SLES12-SP4-SAP-Azure-LI-BYOS-Production
libseccomp2-2.4.1-11.3.2
Image SLES12-SP4-SAP-Azure-VLI-BYOS-Production
libseccomp2-2.4.1-11.3.2
Image SLES12-SP4-SAP-EC2-HVM
libseccomp2-2.4.1-11.3.2
Image SLES12-SP4-SAP-EC2-HVM-BYOS
libseccomp2-2.4.1-11.3.2
Image SLES12-SP4-SAP-GCE
libseccomp2-2.4.1-11.3.2
Image SLES12-SP4-SAP-GCE-BYOS
libseccomp2-2.4.1-11.3.2
Image SLES12-SP4-SAP-OCI-BYOS
libseccomp2-2.4.1-11.3.2
Image SLES12-SP5-Azure-BYOS
libseccomp2-2.4.1-11.3.2
Image SLES12-SP5-Azure-Basic-On-Demand
libseccomp2-2.4.1-11.3.2
Image SLES12-SP5-Azure-HPC-BYOS
libseccomp2-2.4.1-11.3.2
Image SLES12-SP5-Azure-HPC-On-Demand
libseccomp2-2.4.1-11.3.2
Image SLES12-SP5-Azure-SAP-BYOS
libseccomp2-2.4.1-11.3.2
Image SLES12-SP5-Azure-SAP-On-Demand
libseccomp2-2.4.1-11.3.2
Image SLES12-SP5-Azure-Standard-On-Demand
libseccomp2-2.4.1-11.3.2
Image SLES12-SP5-EC2-BYOS
libseccomp2-2.4.1-11.3.2
Image SLES12-SP5-EC2-ECS-On-Demand
libseccomp2-2.4.1-11.3.2
Image SLES12-SP5-EC2-On-Demand
libseccomp2-2.4.1-11.3.2
Image SLES12-SP5-EC2-SAP-BYOS
libseccomp2-2.4.1-11.3.2
Image SLES12-SP5-EC2-SAP-On-Demand
libseccomp2-2.4.1-11.3.2
Image SLES12-SP5-GCE-BYOS
libseccomp2-2.4.1-11.3.2
Image SLES12-SP5-GCE-On-Demand
libseccomp2-2.4.1-11.3.2
Image SLES12-SP5-GCE-SAP-BYOS
libseccomp2-2.4.1-11.3.2
Image SLES12-SP5-GCE-SAP-On-Demand
libseccomp2-2.4.1-11.3.2
Image SLES12-SP5-OCI-BYOS-BYOS
libseccomp2-2.4.1-11.3.2
Image SLES12-SP5-OCI-BYOS-SAP-BYOS
libseccomp2-2.4.1-11.3.2
Image SLES12-SP5-SAP-Azure-LI-BYOS-Production
libseccomp2-2.4.1-11.3.2
Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production
libseccomp2-2.4.1-11.3.2
SUSE Enterprise Storage 5
libseccomp2-2.4.1-11.3.2
libseccomp2-32bit-2.4.1-11.3.2
SUSE Linux Enterprise Desktop 12 SP4
libseccomp2-2.4.1-11.3.2
libseccomp2-32bit-2.4.1-11.3.2
SUSE Linux Enterprise Server 12 SP2-BCL
libseccomp2-2.4.1-11.3.2
libseccomp2-32bit-2.4.1-11.3.2
SUSE Linux Enterprise Server 12 SP2-LTSS
libseccomp2-2.4.1-11.3.2
libseccomp2-32bit-2.4.1-11.3.2
SUSE Linux Enterprise Server 12 SP3-BCL
libseccomp2-2.4.1-11.3.2
libseccomp2-32bit-2.4.1-11.3.2
SUSE Linux Enterprise Server 12 SP3-LTSS
libseccomp2-2.4.1-11.3.2
libseccomp2-32bit-2.4.1-11.3.2
SUSE Linux Enterprise Server 12 SP4
libseccomp2-2.4.1-11.3.2
libseccomp2-32bit-2.4.1-11.3.2
SUSE Linux Enterprise Server 12 SP5
libseccomp2-2.4.1-11.3.2
libseccomp2-32bit-2.4.1-11.3.2
SUSE Linux Enterprise Server for SAP Applications 12 SP2
libseccomp2-2.4.1-11.3.2
libseccomp2-32bit-2.4.1-11.3.2
SUSE Linux Enterprise Server for SAP Applications 12 SP3
libseccomp2-2.4.1-11.3.2
libseccomp2-32bit-2.4.1-11.3.2
SUSE Linux Enterprise Server for SAP Applications 12 SP4
libseccomp2-2.4.1-11.3.2
libseccomp2-32bit-2.4.1-11.3.2
SUSE Linux Enterprise Server for SAP Applications 12 SP5
libseccomp2-2.4.1-11.3.2
libseccomp2-32bit-2.4.1-11.3.2
SUSE Linux Enterprise Software Development Kit 12 SP4
libseccomp-devel-2.4.1-11.3.2
SUSE Linux Enterprise Software Development Kit 12 SP5
libseccomp-devel-2.4.1-11.3.2
SUSE OpenStack Cloud 7
libseccomp2-2.4.1-11.3.2
libseccomp2-32bit-2.4.1-11.3.2
SUSE OpenStack Cloud 8
libseccomp2-2.4.1-11.3.2
libseccomp2-32bit-2.4.1-11.3.2
SUSE OpenStack Cloud Crowbar 8
libseccomp2-2.4.1-11.3.2
libseccomp2-32bit-2.4.1-11.3.2
Ссылки
- Link for SUSE-SU-2019:2941-1
- E-Mail link for SUSE-SU-2019:2941-1
- SUSE Security Ratings
- SUSE Bug 1082318
- SUSE Bug 1128828
- SUSE Bug 1142614
- SUSE CVE CVE-2019-9893 page
Описание
libseccomp before 2.4.0 did not correctly generate 64-bit syscall argument comparisons using the arithmetic operators (LT, GT, LE, GE), which might able to lead to bypassing seccomp filters and potential privilege escalations.
Затронутые продукты
Container caasp/v4/nginx-ingress-controller:beta1:libseccomp2-2.4.1-11.3.2
Container suse/sles12sp3:latest:libseccomp2-2.4.1-11.3.2
HPE Helion OpenStack 8:libseccomp2-2.4.1-11.3.2
HPE Helion OpenStack 8:libseccomp2-32bit-2.4.1-11.3.2
Ссылки
- CVE-2019-9893
- SUSE Bug 1128828