See how rsbac compares to other vendors in security performance
Rule Set Based Access Control (RSBAC) 1.2.2 through 1.2.3 allows access to syscreat, sysopen, and sysmknod inside jails, which could allow local users to gain elevated privileges.
Rule Set Based Access Control (RSBAC) before 1.3.5 does not properly use the Linux Kernel Crypto API for the Linux kernel 2.6.x, which allows context-dependent attackers to bypass authentication controls via unspecified vectors, possibly involving User Management password hashing and unchecked function return codes.