{"id":"CVE-2016-10124","details":"An issue was discovered in Linux Containers (LXC) before 2016-02-22. When executing a program via lxc-attach, the nonpriv session can escape to the parent session by using the TIOCSTI ioctl to push characters into the terminal's input buffer, allowing an attacker to escape the container.","modified":"2026-07-08T12:43:21.367893Z","published":"2017-01-09T08:59:00.153Z","references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2014/12/15/5"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2015/09/03/5"},{"type":"WEB","url":"http://www.securityfocus.com/bid/95404"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/201711-09"},{"type":"FIX","url":"https://github.com/lxc/lxc/commit/e986ea3dfa4a2957f71ae9bfaed406dd6e1ffff6"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/lxc/lxc","events":[{"introduced":"0"},{"last_affected":"823765e50bf4df2f2365bd2590768676634919b7"},{"fixed":"e986ea3dfa4a2957f71ae9bfaed406dd6e1ffff6"}],"database_specific":{"cpe":"cpe:2.3:a:linuxcontainers:lxc:*:rc1:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"2.0.0"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["lxc-2.0.0","lxc-2.0.0.rc15","lxc-2.0.0.rc14","lxc-2.0.0.rc13","lxc-2.0.0.rc12","lxc-2.0.0.rc11","lxc-2.0.0.rc10","lxc-2.0.0.rc9","lxc-2.0.0.rc8","lxc-2.0.0.rc7","lxc-2.0.0.rc6","lxc-2.0.0.rc5","lxc-2.0.0.rc4","lxc-2.0.0.rc3","lxc-2.0.0.rc2","lxc-2.0.0.rc1","lxc-2.0.0.beta2","lxc-2.0.0.beta1","lxc-1.1.0","lxc-1.1.0.rc4","lxc-1.1.0.rc3","lxc-1.1.0.rc2","lxc-1.1.0.rc1","lxc-1.1.0.alpha3","lxc-1.1.0.alpha2","lxc-1.1.0.alpha1","lxc-1.0.0","lxc-1.0.0.rc4","lxc-1.0.0.rc3","lxc-1.0.0.rc2","lxc-1.0.0.rc1","lxc-1.0.0.beta4","lxc-1.0.0.beta3","lxc-1.0.0.beta2","lxc-1.0.0.beta1","lxc-1.0.0.alpha3","lxc-1.0.0.alpha2","lxc-1.0.0.alpha1","lxc-0.9.0","lxc-0.9.0.rc1","lxc-0.9.0.alpha3","lxc-0.9.0.alpha2","lxc-0.9.0.alpha1","lxc-0.8.0","lxc-0.8.0-rc2","lxc-0.7.5","lxc-0.7.4","lxc-0.7.4-rc1","lxc-0.7.3","lxc-0.7.2","lxc-0.7.1","lxc-0.7.0","lxc-0.6.5","lxc_0_6_4","lxc_0_6_3","lxc_0_6_2","lxc_0_6_1","lxc_0_6_0","lxc_0_5_2","lxc_0_5_1","lxc_0_5_0","lxc_0_4_0","lxc_0_2_1","lxc_0_2_0","lxc_0_1_0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-10124.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N"}]}