CVE-2016-2779: Kernel Util-Linux

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

runuser in util-linux allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer.

Affected products

  • Kernel Util-Linux: version 2.24.2-1 only

Published 2017-02-07. Last modified 2026-06-17.