PatchSiren

Firejail Project CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Firejail Project CVE published 2017-01-19

CVE-2016-9016

CVE-2016-9016 is a high-severity Firejail sandbox escape affecting version 0.9.38.4. According to NVD, a local user can abuse a crafted TIOCSTI ioctl call to execute arbitrary commands outside the sandbox boundary. The CVSS v3.0 vector reflects local attack requirements, low attack complexity, low privileges, no user interaction, and a changed scope with high impact to confidentiality, integrity, and availability.