PublicDateAtUSN: 2017-01-09 Candidate: CVE-2016-10124 PublicDate: 2017-01-09 08:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-10124 https://ubuntu.com/security/notices/USN-3375-1 Description: An issue was discovered in Linux Containers (LXC) before 2016-02-22. When executing a program via lxc-attach, the nonpriv session can escape to the parent session by using the TIOCSTI ioctl to push characters into the terminal's input buffer, allowing an attacker to escape the container. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N [8.6 HIGH] Patches_lxc: upstream: https://github.com/lxc/lxc/commit/e986ea3dfa4a2957f71ae9bfaed406dd6e1ffff6 upstream: https://github.com/lxc/lxc/commit/5eacdc3dbd0e45abf3cc90cf0216a7f8ee560abf upstream_lxc: released (1:2.0.0-1) precise_lxc: ignored (reached end-of-life) precise/esm_lxc: DNE (precise was needed) trusty_lxc: released (1.0.10-0ubuntu1.1) trusty/esm_lxc: not-affected (trusty was released [1.0.10-0ubuntu1.1]) vivid/stable-phone-overlay_lxc: ignored (reached end-of-life) vivid/ubuntu-core_lxc: DNE xenial_lxc: not-affected (2.0.7-0ubuntu1~16.04.2) esm-infra/xenial_lxc: not-affected (2.0.7-0ubuntu1~16.04.2) yakkety_lxc: not-affected (2.0.7-0ubuntu1~16.10.2) zesty_lxc: not-affected (2.0.7-0ubuntu2) devel_lxc: not-affected (2.0.8-0ubuntu3)