runuser in util-linux allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer.
oryginał ENCVSS Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HKernel Util Linux
APPKernel2.24.2-1
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje
Powiązane podatności
CVE-2015-5224CRITICAL9.8PL ✓ten sam produkt
util-linux: kolizja nazw plików tymczasowych w funkcji mkostemp
CVE-2018-7738HIGH7.8ten sam produkt
In util-linux before 2.32-rc1, bash-completion/umount allows local users to gain privileges by embedding shell...
CVE-2014-9114HIGH7.8ten sam produkt
Blkid in util-linux before 2.26rc-1 allows local users to execute arbitrary code.
CVE-2007-5191HIGH7.2ten sam produkt
mount and umount in util-linux and loop-aes-utils call the setuid and setgid functions in the wrong order and ...
CVE-2026-13595MEDIUM6.8ten sam produkt
W bibliotece libblkid z util-linux odkryto lukę. Podczas zagnieżdżonego sondowania partycji, narzędzia do anal...