Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2019:2941-1

Опубликовано: 12 нояб. 2019
Источник: suse-cvrf

Описание

Security update for libseccomp

This update for libseccomp fixes the following issues:

Update to new upstream release 2.4.1:

  • Fix a BPF generation bug where the optimizer mistakenly identified duplicate BPF code blocks.

Updated to 2.4.0 (bsc#1128828 CVE-2019-9893):

  • Update the syscall table for Linux v5.0-rc5
  • Added support for the SCMP_ACT_KILL_PROCESS action
  • Added support for the SCMP_ACT_LOG action and SCMP_FLTATR_CTL_LOG attribute
  • Added explicit 32-bit (SCMP_AX_32(...)) and 64-bit (SCMP_AX_64(...)) argument comparison macros to help protect against unexpected sign extension
  • Added support for the parisc and parisc64 architectures
  • Added the ability to query and set the libseccomp API level via seccomp_api_get(3) and seccomp_api_set(3)
  • Return -EDOM on an endian mismatch when adding an architecture to a filter
  • Renumber the pseudo syscall number for subpage_prot() so it no longer conflicts with spu_run()
  • Fix PFC generation when a syscall is prioritized, but no rule exists
  • Numerous fixes to the seccomp-bpf filter generation code
  • Switch our internal hashing function to jhash/Lookup3 to MurmurHash3
  • Numerous tests added to the included test suite, coverage now at ~92%
  • Update our Travis CI configuration to use Ubuntu 16.04
  • Numerous documentation fixes and updates

Update to release 2.3.3:

  • Updated the syscall table for Linux v4.15-rc7

Update to release 2.3.2:

  • Achieved full compliance with the CII Best Practices program
  • Added Travis CI builds to the GitHub repository
  • Added code coverage reporting with the '--enable-code-coverage' configure flag and added Coveralls to the GitHub repository
  • Updated the syscall tables to match Linux v4.10-rc6+
  • Support for building with Python v3.x
  • Allow rules with the -1 syscall if the SCMP_FLTATR_API_TSKIP attribute is set to true
  • Several small documentation fixes
  • ignore make check error for ppc64/ppc64le, bypass bsc#1142614

Список пакетов

Container caasp/v4/nginx-ingress-controller:beta1
libseccomp2-2.4.1-11.3.2
Container suse/sles12sp3:latest
libseccomp2-2.4.1-11.3.2
HPE Helion OpenStack 8
libseccomp2-2.4.1-11.3.2
libseccomp2-32bit-2.4.1-11.3.2
Image SLES12-SP4-Azure-BYOS
libseccomp2-2.4.1-11.3.2
Image SLES12-SP4-EC2-HVM-BYOS
libseccomp2-2.4.1-11.3.2
Image SLES12-SP4-GCE-BYOS
libseccomp2-2.4.1-11.3.2
Image SLES12-SP4-OCI-BYOS
libseccomp2-2.4.1-11.3.2
Image SLES12-SP4-SAP-Azure
libseccomp2-2.4.1-11.3.2
Image SLES12-SP4-SAP-Azure-BYOS
libseccomp2-2.4.1-11.3.2
Image SLES12-SP4-SAP-Azure-LI-BYOS-Production
libseccomp2-2.4.1-11.3.2
Image SLES12-SP4-SAP-Azure-VLI-BYOS-Production
libseccomp2-2.4.1-11.3.2
Image SLES12-SP4-SAP-EC2-HVM
libseccomp2-2.4.1-11.3.2
Image SLES12-SP4-SAP-EC2-HVM-BYOS
libseccomp2-2.4.1-11.3.2
Image SLES12-SP4-SAP-GCE
libseccomp2-2.4.1-11.3.2
Image SLES12-SP4-SAP-GCE-BYOS
libseccomp2-2.4.1-11.3.2
Image SLES12-SP4-SAP-OCI-BYOS
libseccomp2-2.4.1-11.3.2
Image SLES12-SP5-Azure-BYOS
libseccomp2-2.4.1-11.3.2
Image SLES12-SP5-Azure-Basic-On-Demand
libseccomp2-2.4.1-11.3.2
Image SLES12-SP5-Azure-HPC-BYOS
libseccomp2-2.4.1-11.3.2
Image SLES12-SP5-Azure-HPC-On-Demand
libseccomp2-2.4.1-11.3.2
Image SLES12-SP5-Azure-SAP-BYOS
libseccomp2-2.4.1-11.3.2
Image SLES12-SP5-Azure-SAP-On-Demand
libseccomp2-2.4.1-11.3.2
Image SLES12-SP5-Azure-Standard-On-Demand
libseccomp2-2.4.1-11.3.2
Image SLES12-SP5-EC2-BYOS
libseccomp2-2.4.1-11.3.2
Image SLES12-SP5-EC2-ECS-On-Demand
libseccomp2-2.4.1-11.3.2
Image SLES12-SP5-EC2-On-Demand
libseccomp2-2.4.1-11.3.2
Image SLES12-SP5-EC2-SAP-BYOS
libseccomp2-2.4.1-11.3.2
Image SLES12-SP5-EC2-SAP-On-Demand
libseccomp2-2.4.1-11.3.2
Image SLES12-SP5-GCE-BYOS
libseccomp2-2.4.1-11.3.2
Image SLES12-SP5-GCE-On-Demand
libseccomp2-2.4.1-11.3.2
Image SLES12-SP5-GCE-SAP-BYOS
libseccomp2-2.4.1-11.3.2
Image SLES12-SP5-GCE-SAP-On-Demand
libseccomp2-2.4.1-11.3.2
Image SLES12-SP5-OCI-BYOS-BYOS
libseccomp2-2.4.1-11.3.2
Image SLES12-SP5-OCI-BYOS-SAP-BYOS
libseccomp2-2.4.1-11.3.2
Image SLES12-SP5-SAP-Azure-LI-BYOS-Production
libseccomp2-2.4.1-11.3.2
Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production
libseccomp2-2.4.1-11.3.2
SUSE Enterprise Storage 5
libseccomp2-2.4.1-11.3.2
libseccomp2-32bit-2.4.1-11.3.2
SUSE Linux Enterprise Desktop 12 SP4
libseccomp2-2.4.1-11.3.2
libseccomp2-32bit-2.4.1-11.3.2
SUSE Linux Enterprise Server 12 SP2-BCL
libseccomp2-2.4.1-11.3.2
libseccomp2-32bit-2.4.1-11.3.2
SUSE Linux Enterprise Server 12 SP2-LTSS
libseccomp2-2.4.1-11.3.2
libseccomp2-32bit-2.4.1-11.3.2
SUSE Linux Enterprise Server 12 SP3-BCL
libseccomp2-2.4.1-11.3.2
libseccomp2-32bit-2.4.1-11.3.2
SUSE Linux Enterprise Server 12 SP3-LTSS
libseccomp2-2.4.1-11.3.2
libseccomp2-32bit-2.4.1-11.3.2
SUSE Linux Enterprise Server 12 SP4
libseccomp2-2.4.1-11.3.2
libseccomp2-32bit-2.4.1-11.3.2
SUSE Linux Enterprise Server 12 SP5
libseccomp2-2.4.1-11.3.2
libseccomp2-32bit-2.4.1-11.3.2
SUSE Linux Enterprise Server for SAP Applications 12 SP2
libseccomp2-2.4.1-11.3.2
libseccomp2-32bit-2.4.1-11.3.2
SUSE Linux Enterprise Server for SAP Applications 12 SP3
libseccomp2-2.4.1-11.3.2
libseccomp2-32bit-2.4.1-11.3.2
SUSE Linux Enterprise Server for SAP Applications 12 SP4
libseccomp2-2.4.1-11.3.2
libseccomp2-32bit-2.4.1-11.3.2
SUSE Linux Enterprise Server for SAP Applications 12 SP5
libseccomp2-2.4.1-11.3.2
libseccomp2-32bit-2.4.1-11.3.2
SUSE Linux Enterprise Software Development Kit 12 SP4
libseccomp-devel-2.4.1-11.3.2
SUSE Linux Enterprise Software Development Kit 12 SP5
libseccomp-devel-2.4.1-11.3.2
SUSE OpenStack Cloud 7
libseccomp2-2.4.1-11.3.2
libseccomp2-32bit-2.4.1-11.3.2
SUSE OpenStack Cloud 8
libseccomp2-2.4.1-11.3.2
libseccomp2-32bit-2.4.1-11.3.2
SUSE OpenStack Cloud Crowbar 8
libseccomp2-2.4.1-11.3.2
libseccomp2-32bit-2.4.1-11.3.2

Описание

libseccomp before 2.4.0 did not correctly generate 64-bit syscall argument comparisons using the arithmetic operators (LT, GT, LE, GE), which might able to lead to bypassing seccomp filters and potential privilege escalations.


Затронутые продукты
Container caasp/v4/nginx-ingress-controller:beta1:libseccomp2-2.4.1-11.3.2
Container suse/sles12sp3:latest:libseccomp2-2.4.1-11.3.2
HPE Helion OpenStack 8:libseccomp2-2.4.1-11.3.2
HPE Helion OpenStack 8:libseccomp2-32bit-2.4.1-11.3.2

Ссылки
Уязвимость SUSE-SU-2019:2941-1