{"id":"CVE-2019-9893","details":"libseccomp before 2.4.0 did not correctly generate 64-bit syscall argument comparisons using the arithmetic operators (LT, GT, LE, GE), which might able to lead to bypassing seccomp filters and potential privilege escalations.","modified":"2026-07-08T16:28:21.468613Z","published":"2019-03-21T16:01:17.687Z","related":["SUSE-SU-2019:2517-1","SUSE-SU-2019:2941-1","openSUSE-SU-2019:2280-1","openSUSE-SU-2019:2283-1","openSUSE-SU-2024:10989-1"],"references":[{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00022.html"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00027.html"},{"type":"WEB","url":"https://usn.ubuntu.com/4001-1/"},{"type":"WEB","url":"https://usn.ubuntu.com/4001-2/"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:3624"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/201904-18"},{"type":"FIX","url":"https://github.com/seccomp/libseccomp/issues/139"},{"type":"FIX","url":"https://seclists.org/oss-sec/2019/q1/179"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/seccomp/libseccomp","events":[{"introduced":"0"},{"fixed":"4d64011741375bb1a4ba7d71905ca37b97885083"}],"database_specific":{"cpe":"cpe:2.3:a:libseccomp_project:libseccomp:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"2.4.0"}],"source":"CPE_RANGE"}}],"versions":["v2.2.0","v2.1.1","v2.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-9893.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}