PatchSiren

Kernel CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Kernel CVE published 2017-02-07

CVE-2016-2779

CVE-2016-2779 is a high-severity local security issue in util-linux runuser. According to the CVE description, a crafted TIOCSTI ioctl call can push characters into the terminal input buffer and let a local user escape to the parent session. NVD rates the issue as High and maps it to a vulnerable util-linux build in its CPE criteria.