First published: Thu Feb 25 2016(Updated: )
runuser in util-linux allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Kernel Util-linux | =2.24.2-1 | |
debian/util-linux | 2.36.1-8+deb11u2 2.38.1-5+deb12u1 2.40.2-1 2.40.2-6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.