Summary
One bug could silently weaken a generated seccomp policy when multiple 64-bit comparison rules were merged incorrectly. Two more bugs involved oversized BPF programs: an instruction-count overflow could corrupt the heap, while an error path could leave a dangling buffer pointer and later double-free it.
All three upstream advisories list no known CVE, directly name XGPT in the reporter credit, and point users to libseccomp 2.6.1. The ledger groups them as one coordinated release campaign while preserving all three GHSA identifiers.
References
- libseccomp advisory: GHSA-4q85-33p6-j5g6
- libseccomp advisory: GHSA-46fr-jh49-xvhx
- libseccomp advisory: GHSA-2hqh-5c36-grrm
- libseccomp 2.6.1 release
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.