CVE-2017-18367: Libseccomp-Golang Project Libseccomp-Golang

High severity, CVSS 7.5. EPSS: 2.4% chance of exploitation in the next 30 days.

libseccomp-golang 0.9.0 and earlier incorrectly generates BPFs that OR multiple arguments rather than ANDing them. A process running under a restrictive seccomp filter that specified multiple syscall arguments could bypass intended access restrictions by specifying a single matching argument.

Affected products

Published 2019-04-24. Last modified 2026-06-17.