CVE-2016-2781: Input Validation
chroot in GNU coreutils when used with --userspec allows local users to escape to the parent session via a crafted TIOCSTI ioctl call which pushes characters to the terminal's input buffer.
Other sources
chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer.
— Debian
util-linux could allow a local attacker to gain elevated privileges on the system, caused by an error when executing a program via "chroot --userspec=someuser:somegroup / /path/to/test". An attacker could exploit this vulnerability using the TIOCSTI ioctl to hijack the tty and gain elevated privileges on the system.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2781?
CVE-2016-2781 is considered a high severity vulnerability as it allows local users to potentially escalate privileges.
How do I fix CVE-2016-2781?
To fix CVE-2016-2781, update your GNU coreutils and other affected software to the latest patched versions.
Who is affected by CVE-2016-2781?
CVE-2016-2781 affects various versions of GNU coreutils and IBM Cloud Pak for Business Automation.
What systems are vulnerable to CVE-2016-2781?
Systems running unpatched versions of GNU coreutils, specifically versions up to 8.32-4 and 9.4-3.1, are vulnerable to CVE-2016-2781.
Can CVE-2016-2781 be exploited remotely?
CVE-2016-2781 requires local access to the affected system to exploit the vulnerability.