CVE-2016-2779: High severity kernel util-linux vulnerability
runuser in util-linux allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2779?
CVE-2016-2779 has been assigned a medium severity rating due to its potential to allow local users to escape to the parent session.
How do I fix CVE-2016-2779?
To fix CVE-2016-2779, update the util-linux package to version 2.36.1-8+deb11u2, 2.38.1-5+deb12u1, or 2.40.2-1 or higher.
Which software is affected by CVE-2016-2779?
CVE-2016-2779 affects the util-linux package, specifically versions prior to the patched updates mentioned.
What is the exploit vector for CVE-2016-2779?
The exploit vector for CVE-2016-2779 is a crafted TIOCSTI ioctl call that targets local user sessions.
Are there any known attacks exploiting CVE-2016-2779?
As of now, there are no widely reported attacks specifically exploiting CVE-2016-2779, but its vulnerability poses a risk to local user environments.