netfoil's optional seccomp sandboxing was not applied
Moderate severity
GitHub Reviewed
Published
Apr 22, 2026
in
tinfoil-factory/netfoil
•
Updated Apr 29, 2026
Description
Published to the GitHub Advisory Database
Apr 29, 2026
Reviewed
Apr 29, 2026
Last updated
Apr 29, 2026
Summary
The optional flag
--filter-system-callswas not applied even if specified.Details
This is a defense in depth feature to apply additional seccomp filters after the binary has started. The example config also sandboxes the binary with systemd.
Impact
Reduced sandboxing of the netfoil binary.
References