{"id":"SUSE-SU-2019:2941-1","summary":"Security update for libseccomp","details":"This update for libseccomp fixes the following issues:\n\nUpdate to new upstream release 2.4.1:\n\n* Fix a BPF generation bug where the optimizer mistakenly\n  identified duplicate BPF code blocks.\n\nUpdated to 2.4.0 (bsc#1128828 CVE-2019-9893):\n\n* Update the syscall table for Linux v5.0-rc5\n* Added support for the SCMP_ACT_KILL_PROCESS action\n* Added support for the SCMP_ACT_LOG action and SCMP_FLTATR_CTL_LOG attribute\n* Added explicit 32-bit (SCMP_AX_32(...)) and 64-bit (SCMP_AX_64(...)) argument comparison macros to help protect against unexpected sign extension\n* Added support for the parisc and parisc64 architectures\n* Added the ability to query and set the libseccomp API level via seccomp_api_get(3) and seccomp_api_set(3)\n* Return -EDOM on an endian mismatch when adding an architecture to a filter\n* Renumber the pseudo syscall number for subpage_prot() so it no longer conflicts with spu_run()\n* Fix PFC generation when a syscall is prioritized, but no rule exists\n* Numerous fixes to the seccomp-bpf filter generation code\n* Switch our internal hashing function to jhash/Lookup3 to MurmurHash3\n* Numerous tests added to the included test suite, coverage now at ~92%\n* Update our Travis CI configuration to use Ubuntu 16.04\n* Numerous documentation fixes and updates\n\nUpdate to release 2.3.3:\n\n* Updated the syscall table for Linux v4.15-rc7\n\nUpdate to release 2.3.2:\n\n* Achieved full compliance with the CII Best Practices program\n* Added Travis CI builds to the GitHub repository\n* Added code coverage reporting with the '--enable-code-coverage' configure\n  flag and added Coveralls to the GitHub repository\n* Updated the syscall tables to match Linux v4.10-rc6+\n* Support for building with Python v3.x\n* Allow rules with the -1 syscall if the SCMP\\_FLTATR\\_API\\_TSKIP attribute is\n  set to true\n* Several small documentation fixes\n\n- ignore make check error for ppc64/ppc64le, bypass bsc#1142614\n","modified":"2026-03-11T07:13:10.499131Z","published":"2019-11-12T09:04:16Z","related":["CVE-2019-9893"],"upstream":["CVE-2019-9893"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2019/suse-su-20192941-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1082318"},{"type":"REPORT","url":"https://bugzilla.suse.com/1128828"},{"type":"REPORT","url":"https://bugzilla.suse.com/1142614"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-9893"}],"affected":[{"package":{"name":"libseccomp","ecosystem":"SUSE:HPE Helion OpenStack 8","purl":"pkg:rpm/suse/libseccomp&distro=HPE%20Helion%20OpenStack%208"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.1-11.3.2"}]}],"ecosystem_specific":{"binaries":[{"libseccomp2-32bit":"2.4.1-11.3.2","libseccomp2":"2.4.1-11.3.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2019:2941-1.json"}},{"package":{"name":"libseccomp","ecosystem":"SUSE:OpenStack Cloud 7","purl":"pkg:rpm/suse/libseccomp&distro=SUSE%20OpenStack%20Cloud%207"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.1-11.3.2"}]}],"ecosystem_specific":{"binaries":[{"libseccomp2-32bit":"2.4.1-11.3.2","libseccomp2":"2.4.1-11.3.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2019:2941-1.json"}},{"package":{"name":"libseccomp","ecosystem":"SUSE:OpenStack Cloud 8","purl":"pkg:rpm/suse/libseccomp&distro=SUSE%20OpenStack%20Cloud%208"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.1-11.3.2"}]}],"ecosystem_specific":{"binaries":[{"libseccomp2-32bit":"2.4.1-11.3.2","libseccomp2":"2.4.1-11.3.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2019:2941-1.json"}},{"package":{"name":"libseccomp","ecosystem":"SUSE:OpenStack Cloud Crowbar 8","purl":"pkg:rpm/suse/libseccomp&distro=SUSE%20OpenStack%20Cloud%20Crowbar%208"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.1-11.3.2"}]}],"ecosystem_specific":{"binaries":[{"libseccomp2-32bit":"2.4.1-11.3.2","libseccomp2":"2.4.1-11.3.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2019:2941-1.json"}},{"package":{"name":"libseccomp","ecosystem":"SUSE:Linux Enterprise Desktop 12 SP4","purl":"pkg:rpm/suse/libseccomp&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.1-11.3.2"}]}],"ecosystem_specific":{"binaries":[{"libseccomp2-32bit":"2.4.1-11.3.2","libseccomp2":"2.4.1-11.3.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2019:2941-1.json"}},{"package":{"name":"libseccomp","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP2","purl":"pkg:rpm/suse/libseccomp&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.1-11.3.2"}]}],"ecosystem_specific":{"binaries":[{"libseccomp2-32bit":"2.4.1-11.3.2","libseccomp2":"2.4.1-11.3.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2019:2941-1.json"}},{"package":{"name":"libseccomp","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP3","purl":"pkg:rpm/suse/libseccomp&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.1-11.3.2"}]}],"ecosystem_specific":{"binaries":[{"libseccomp2-32bit":"2.4.1-11.3.2","libseccomp2":"2.4.1-11.3.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2019:2941-1.json"}},{"package":{"name":"libseccomp","ecosystem":"SUSE:Linux Enterprise Software Development Kit 12 SP4","purl":"pkg:rpm/suse/libseccomp&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.1-11.3.2"}]}],"ecosystem_specific":{"binaries":[{"libseccomp-devel":"2.4.1-11.3.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2019:2941-1.json"}},{"package":{"name":"libseccomp","ecosystem":"SUSE:Linux Enterprise Software Development Kit 12 SP5","purl":"pkg:rpm/suse/libseccomp&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.1-11.3.2"}]}],"ecosystem_specific":{"binaries":[{"libseccomp-devel":"2.4.1-11.3.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2019:2941-1.json"}},{"package":{"name":"libseccomp","ecosystem":"SUSE:Linux Enterprise Server 12 SP2-LTSS","purl":"pkg:rpm/suse/libseccomp&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.1-11.3.2"}]}],"ecosystem_specific":{"binaries":[{"libseccomp2-32bit":"2.4.1-11.3.2","libseccomp2":"2.4.1-11.3.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2019:2941-1.json"}},{"package":{"name":"libseccomp","ecosystem":"SUSE:Linux Enterprise Server 12 SP2-BCL","purl":"pkg:rpm/suse/libseccomp&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCL"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.1-11.3.2"}]}],"ecosystem_specific":{"binaries":[{"libseccomp2-32bit":"2.4.1-11.3.2","libseccomp2":"2.4.1-11.3.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2019:2941-1.json"}},{"package":{"name":"libseccomp","ecosystem":"SUSE:Linux Enterprise Server 12 SP3-LTSS","purl":"pkg:rpm/suse/libseccomp&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.1-11.3.2"}]}],"ecosystem_specific":{"binaries":[{"libseccomp2-32bit":"2.4.1-11.3.2","libseccomp2":"2.4.1-11.3.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2019:2941-1.json"}},{"package":{"name":"libseccomp","ecosystem":"SUSE:Linux Enterprise Server 12 SP3-BCL","purl":"pkg:rpm/suse/libseccomp&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-BCL"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.1-11.3.2"}]}],"ecosystem_specific":{"binaries":[{"libseccomp2-32bit":"2.4.1-11.3.2","libseccomp2":"2.4.1-11.3.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2019:2941-1.json"}},{"package":{"name":"libseccomp","ecosystem":"SUSE:Linux Enterprise Server 12 SP4","purl":"pkg:rpm/suse/libseccomp&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.1-11.3.2"}]}],"ecosystem_specific":{"binaries":[{"libseccomp2":"2.4.1-11.3.2","libseccomp2-32bit":"2.4.1-11.3.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2019:2941-1.json"}},{"package":{"name":"libseccomp","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP4","purl":"pkg:rpm/suse/libseccomp&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.1-11.3.2"}]}],"ecosystem_specific":{"binaries":[{"libseccomp2-32bit":"2.4.1-11.3.2","libseccomp2":"2.4.1-11.3.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2019:2941-1.json"}},{"package":{"name":"libseccomp","ecosystem":"SUSE:Linux Enterprise Server 12 SP5","purl":"pkg:rpm/suse/libseccomp&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.1-11.3.2"}]}],"ecosystem_specific":{"binaries":[{"libseccomp2-32bit":"2.4.1-11.3.2","libseccomp2":"2.4.1-11.3.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2019:2941-1.json"}},{"package":{"name":"libseccomp","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP5","purl":"pkg:rpm/suse/libseccomp&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.1-11.3.2"}]}],"ecosystem_specific":{"binaries":[{"libseccomp2-32bit":"2.4.1-11.3.2","libseccomp2":"2.4.1-11.3.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2019:2941-1.json"}},{"package":{"name":"libseccomp","ecosystem":"SUSE:Enterprise Storage 5","purl":"pkg:rpm/suse/libseccomp&distro=SUSE%20Enterprise%20Storage%205"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.1-11.3.2"}]}],"ecosystem_specific":{"binaries":[{"libseccomp2-32bit":"2.4.1-11.3.2","libseccomp2":"2.4.1-11.3.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2019:2941-1.json"}}],"schema_version":"1.7.5"}