runuser in util-linux allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer.
CVSS Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HKernel Util Linux
APPKernel2.24.2-1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References
Related vulnerabilities
CVE-2015-5224CRITICAL9.8PL ✓same product
util-linux: kolizja nazw plików tymczasowych w funkcji mkostemp
CVE-2018-7738HIGH7.8same product
In util-linux before 2.32-rc1, bash-completion/umount allows local users to gain privileges by embedding shell...
CVE-2014-9114HIGH7.8same product
Blkid in util-linux before 2.26rc-1 allows local users to execute arbitrary code.
CVE-2007-5191HIGH7.2same product
mount and umount in util-linux and loop-aes-utils call the setuid and setgid functions in the wrong order and ...
CVE-2026-13595MEDIUM6.8same product
W bibliotece libblkid z util-linux odkryto lukę. Podczas zagnieżdżonego sondowania partycji, narzędzia do anal...