Opened 3 months ago

Closed 2 months ago

#23546 closed enhancement (fixed)

libseccomp-2.6.1

Reported by: Bruce Dubbs Owned by: SecurityAdvisory
Priority: elevated Milestone: 98-Security
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New point version.

Change History (3)

comment:1 by Joe Locash, 3 months ago

Owner: changed from blfs-book to Joe Locash
Status: new → assigned

comment:2 by Joe Locash, 3 months ago

Milestone: 13.1 → 98-Security
Owner: changed from Joe Locash to SecurityAdvisory
Priority: normal → elevated
Status: assigned → new
* Version 2.6.1 - July 1, 2026
- Update the syscall table for Linux v7.1.0-rc4
- Fix incorrect 64-bit comparison merge that can weaken libseccomp filters.
  See GitHub Advisory GHSA-4q85-33p6-j5g6
- Fix issue where oversized libseccomp filters can trigger a double free.
  See GitHub Advisory GHSA-46fr-jh49-xvhx
- Fix issue where oversized libseccomp filters can trigger a heap corruption.
  See GitHub Advisory GHSA-2hqh-5c36-grrm
- Fix struct aliasing undefined behavior in the internal libseccomp hash
  algorithm
- Fix issue where extraneous bytes were being copied to the destination
  buffer in seccomp_export_bpf_mem()
- Fix a bug where merged libseccomp filters failed to merge the notify_used
  flag, leading to no listener file descriptor being generated
- Update python shebang to point to python3
- Add documentation for seccomp_transaction_start()
- Since support for s390 has been removed from the upstream Linux kernel,
  freeze libseccomp's s390 syscall table at Linux v6.18

Fixed at 3bd3fea3d7. Leaving open for SA.

comment:3 by Bruce Dubbs, 2 months ago

Resolution: → fixed
Status: new → closed

Advisory sa-13.0-170 has been issued.

Note: See TracTickets for help on using tickets.