seccomp

2 articles
sort: new top best
clear filter
0 5/10

Execwall is a Rust-based execution firewall for AI agents that mitigates prompt injection attacks via seccomp-BPF filtering, command allowlisting, and namespace isolation, demonstrated against CVE-2026-2256 in ModelScope's agent framework.

CVE-2026-2256 ModelScope ms-agent Execwall sundarsub
sentra · 20 hours ago · details · hn
0 7/10

Comprehensive technical comparison of FreeBSD's Capsicum and Linux's seccomp-bpf sandboxing models, analyzing their opposite architectural philosophies (capability subtraction vs. syscall filtration) and demonstrating why Capsicum's structural approach is immune to bypass vulnerabilities like CVE-2022-30594 that affect filter-based systems.

FreeBSD Linux Capsicum seccomp seccomp-bpf Robert Watson Jonathan Anderson Andrea Arcangeli Will Drewry CVE-2022-30594 USENIX Security tcpdump BPF PTRACE_SEIZE
vivianvoss.net · vermaden · 5 days ago · details · hn