cbcvebase.
CVE-2016-10124
published 2017-01-09

CVE-2016-10124: An issue was discovered in Linux Containers (LXC) before 2016-02-22. When executing a program via lxc-attach, the nonpriv session can escape to the parent…

PriorityP340high8.6CVSS 3.0
AVNACLPRNUINSCCNIHAN
EPSS
1.53%
71.9th percentile
An issue was discovered in Linux Containers (LXC) before 2016-02-22. When executing a program via lxc-attach, the nonpriv session can escape to the parent session by using the TIOCSTI ioctl to push characters into the terminal's input buffer, allowing an attacker to escape the container.

Affected

6 ranges
VendorProductVersion rangeFixed in
debianlxc< lxc 1:2.0.0-1 (bookworm)lxc 1:2.0.0-1 (bookworm)
linuxcontainerslxc<= 2.0.0
linuxcontainerslxc>= 0 < 1:2.0.0-11:2.0.0-1
linuxcontainerslxc>= 0 < 1:2.0.0-11:2.0.0-1
linuxcontainerslxc>= 0 < 1:2.0.0-11:2.0.0-1
linuxcontainerslxc>= 0 < 1:2.0.0-11:2.0.0-1

CVSS provenance

nvdv3.08.6HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv8.6HIGH
vendor_debian8.6HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.