All findings

xgpt-libseccomp-ghsa-cluster medium

XGPT finds three libseccomp filter-generation vulnerabilities

Three upstream advisories directly credit Feng Xue with XGPT for a filter-policy weakening bug, a double-free, and heap corruption in oversized BPF generation.

Bug class
Incorrect security-policy generation, double-free, and heap corruption
Affected codebase
libseccomp
Credited system
ThreatBook XGPT
Disclosed
July 1, 2026
Attribution
Direct source attribution
Severity
medium
Source status: The three upstream libseccomp advisories directly credit Feng Xue w/XGPT (ThreatBook), state that no CVE is known, and identify libseccomp 2.6.1 as the patched release.

Summary

One bug could silently weaken a generated seccomp policy when multiple 64-bit comparison rules were merged incorrectly. Two more bugs involved oversized BPF programs: an instruction-count overflow could corrupt the heap, while an error path could leave a dangling buffer pointer and later double-free it.

All three upstream advisories list no known CVE, directly name XGPT in the reporter credit, and point users to libseccomp 2.6.1. The ledger groups them as one coordinated release campaign while preserving all three GHSA identifiers.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.