An issue was discovered in Linux Containers (LXC) before 2016-02-22. When executing a program via lxc-attach, the nonpriv session can escape to the parent session by using the TIOCSTI ioctl to push characters into the terminal's input buffer, allowing an attacker to escape the container.
{
"binaries": [
{
"binary_version": "1.0.10-0ubuntu1.1",
"binary_name": "liblxc1"
},
{
"binary_version": "1.0.10-0ubuntu1.1",
"binary_name": "lxc"
},
{
"binary_version": "1.0.10-0ubuntu1.1",
"binary_name": "lxc-dev"
},
{
"binary_version": "1.0.10-0ubuntu1.1",
"binary_name": "lxc-templates"
},
{
"binary_version": "1.0.10-0ubuntu1.1",
"binary_name": "lxc-tests"
},
{
"binary_version": "1.0.10-0ubuntu1.1",
"binary_name": "python3-lxc"
}
],
"availability": "No subscription required"
}