Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-80090

Upgrade libseccomp on both CentOS 9 & 10

Linking RHIVOS CVEs to...Migration: Automation ...Sync from "Extern...XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done-Errata
    • Icon: Blocker Blocker
    • rhel-10.1
    • rhel-10.0.beta
    • libseccomp
    • None
    • libseccomp-2.5.6-1.el10
    • No
    • Moderate
    • rhel-security-special-projects
    • ssg_security
    • 2
    • 3
    • No
    • SECENGSP Cycle 22, SECENGSP Cycle 23
    • Release Note Not Required
    • All
    • None

      libseccomp in both CentOS 9 & 10 is "old" and missing the knowledge of recent syscalls. When using docker or podman to run non-privileged containers, seccomp is actually filtering these syscalls which might be used by more recent OS containers, like for example fchmodat2 used by the glibc in RHEL 10 or Fedora. We should let syscalls actually implemented by the kernel be used instead of using the glibc fallback code in these cases.

      Thus I propose we upgrade libseccomp to the latest version 2.5.x (I doubt you will want to go for 2.6.0 for now).

              rh-ee-aprikryl Adam Prikryl
              romain.geissler@amadeus.com Romain Geissler (Inactive)
              Anderson Toshiyuki Sasaki Anderson Toshiyuki Sasaki
              SSG Security QE SSG Security QE
              Votes:
              1 Vote for this issue
              Watchers:
              10 Start watching this issue

                Created:
                Updated:
                Resolved: