CVE-2017-18367 describes a vulnerability in libseccomp-golang versions 0.9.0 and earlier, where incorrectly generated Berkeley Packet Filters (BPFs) used logical OR operations instead of AND operations for multiple syscall arguments. This flaw allowed a process operating under a restrictive seccomp filter to bypass intended access restrictions by satisfying only one of the specified arguments. Rated with a CVSS score of 7.5 (High), this vulnerability has a low attack complexity and could lead to high integrity impacts, though it does not affect confidentiality or availability. There is no evidence of active exploitation, no public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage, suggesting it is not widely targeted.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.9.0CPE matchmatch criteria | cpe:2.3:a:libseccomp-golang_project:libseccomp-golang:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.