Security Advisory

CVE-2016-10124

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2017-01-09 08:48:00
Last updated 2024-08-06 03:14:42
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

An issue was discovered in Linux Containers (LXC) before 2016-02-22. When executing a program via lxc-attach, the nonpriv session can escape to the parent session by using the TIOCSTI ioctl to push characters into the terminal's input buffer, allowing an attacker to escape the container.