Severity
10.0CRITICAL
EPSS
10.4%
top 6.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 29
Latest updateMar 16

Description

When executing a program via the bubblewrap sandbox, the nonpriv session can escape to the parent session by using the TIOCSTI ioctl to push characters into the terminal's input buffer, allowing an attacker to escape the sandbox.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HExploitability: 3.9 | Impact: 6.0

Affected Packages3 packages

Debianbubblewrap< 0.1.5-2+3
CVEListV5flatpak/flatpak< 1.10.8+3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-m28g-vfcm-85ff: When executing a program via the bubblewrap sandbox, the nonpriv session can escape to the parent session by using the TIOCSTI ioctl to push character2022-05-13
OSV
CVE-2017-5226: When executing a program via the bubblewrap sandbox, the nonpriv session can escape to the parent session by using the TIOCSTI ioctl to push character2017-03-29
CVEList
CVE-2017-5226: When executing a program via the bubblewrap sandbox, the nonpriv session can escape to the parent session by using the TIOCSTI ioctl to push character2017-03-29

📋Vendor Advisories

4
Red Hat
flatpak: TIOCLINUX can send commands outside sandbox if running on a virtual console2023-03-16
Red Hat
webkitgtk: Improper access management to CLONE_NEWUSER and the TIOCSTI ioctl2020-07-10
Red Hat
flatpak: Sandbox bypass via IOCSTI (incomplete fix for CVE-2017-5226)2019-03-22
Debian
CVE-2017-5226: bubblewrap - When executing a program via the bubblewrap sandbox, the nonpriv session can esc...2017

💬Community

6
Bugzilla
CVE-2020-13753 webkitgtk: Improper access management to CLONE_NEWUSER and the TIOCSTI ioctl2020-09-16
Bugzilla
CVE-2019-10063 flatpak: Sandbox bypass via IOCSTI (incomplete fix for CVE-2017-5226) [fedora-all]2019-04-04
Bugzilla
CVE-2019-10063 flatpak: Sandbox bypass via IOCSTI (incomplete fix for CVE-2017-5226)2019-04-04
Bugzilla
CVE-2017-5226 bubblewrap: Nonprivileged session can escape to the parent session by using the TIOCSTI ioctl2017-01-10
Bugzilla
CVE-2017-5226 bubblewrap: Nonprivileged session can escape to the parent session by using the TIOCSTI ioctl [epel-7]2017-01-10
CVE-2017-5226 (CRITICAL CVSS 10) | When executing a program via the bu | cvebase.io