PoC Index

CVE-2017-5226

CRITICAL 10.0EPSS 3.2%

When executing a program via the bubblewrap sandbox, the nonpriv session can escape to the parent session by using the TIOCSTI ioctl to push characters into the terminal's input buffer, allowing an attacker to escape the sandbox.

CVSS v3.0
10.0 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
3.17% chance of exploitation in the next 30 days, 87th percentile
Published
2017-03-29
Updated
2024-08-05

Proof-of-concept exploits (1)

References

Related