CVE-2016-2781: GNU Coreutils

Medium severity, CVSS 4.6. EPSS: 0.4% chance of exploitation in the next 30 days.

chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer.

Affected products

  • GNU Coreutils: any version

Published 2017-02-07. Last modified 2026-06-17.