Back to Database
Status published
High
CVE-2016-2779
runuser in util-linux allows local users to escape to the...
Vulnerability Description
runuser in util-linux allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2016-2779
Credits & Attribution
No credits recorded in the NVD database.
References
More from kernel
View All →CVE-2021-37600
An integer overflow in util-linux through 2.37.1 can potentially cause...
Medium
5.5
CVE-2020-21583
An issue was discovered in hwclock.13-v2.27 allows attackers to gain...
Medium
6.7
CVE-2018-7738
In util-linux before 2.32-rc1, bash-completion/umount allows local users to gain...
High
7.8
CVE-2018-1118
Linux kernel vhost since version 4.8 does not properly initialize...
Low
2.3
CVE-2018-1108
kernel drivers before version 4.17-rc1 are vulnerable to a weakness...
Medium
5.9
Affected Vendor
kernel
View all reports →Affected Software
util-linux
Vulnerable Versions:
2.24.2-1
Timeline
Official Publish:
February 7th, 2017
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.