CVE-2016-2781: GNU Coreutils
Medium severity, CVSS 4.6. EPSS: 0.4% chance of exploitation in the next 30 days.
chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer.
Affected products
- GNU Coreutils: any version
Published 2017-02-07. Last modified 2026-06-17.