In Firejail before 0.9.60, seccomp filters are writable inside the jail, leading to a lack of intended seccomp restrictions for a process that is joined to the jail after a filter has been modified by an attacker.
| Software | From | Fixed in |
|---|---|---|
| firejail_project / firejail | - | 0.9.60 |