CVE-2016-10124
Last modified
CVE-2016-10124 is a vulnerability of currently unknown severity. An issue was discovered in Linux Containers (LXC) before 2016-02-22. When executing a program via lxc-attach, the nonpriv session can escape to the parent session by using the TIOCSTI ioctl to push characters into the terminal's input buffer, allowing an attacker to escape the container.. EPSS estimates a 1.53% chance of exploitation in the next 30 days.
Description
An issue was discovered in Linux Containers (LXC) before 2016-02-22. When executing a program via lxc-attach, the nonpriv session can escape to the parent session by using the TIOCSTI ioctl to push characters into the terminal's input buffer, allowing an attacker to escape the container.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Linuxcontainers | Lxc | <= 2.0.0 | Rc1 |
References
- https://github.com/lxc/lxc/commit/e986ea3dfa4a2957f71ae9bfaed406dd6e1ffff6Issue Tracking, Patch, Third Party Advisory
- https://github.com/lxc/lxc/commit/e986ea3dfa4a2957f71ae9bfaed406dd6e1ffff6Issue Tracking, Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-10124?
How severe is CVE-2016-10124?
How do I fix CVE-2016-10124?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2016
- CVE-2016-10119Firejail uses 0777 permissions when mounting /tmp, which all…
- CVE-2016-1012Adobe Flash Player before 18.0.0.343 and 19.x through 21.x b…8.8
- CVE-2016-10120Firejail uses 0777 permissions when mounting (1) /dev, (2) /…
- CVE-2016-10121Firejail uses weak permissions for /dev/shm/firejail and pos…
- CVE-2016-10122Firejail does not properly clean environment variables, whic…
- CVE-2016-10123Firejail allows --chroot when seccomp is not supported, whic…
- CVE-2016-10125D-Link DGS-1100 devices with Rev.B firmware 1.01.018 have a …
- CVE-2016-10126Splunk Web in Splunk Enterprise 5.0.x before 5.0.17, 6.0.x b…
- CVE-2016-10127PySAML2 allows remote attackers to conduct XML external enti…
- CVE-2016-10128Buffer overflow in the git_pkt_parse_line function in transp…
- CVE-2016-10129The Git Smart Protocol support in libgit2 before 0.24.6 and …
- CVE-2016-1013Use-after-free vulnerability in Adobe Flash Player before 18…8.8
Are you affected by CVE-2016-10124?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
