An issue was discovered in Linux Containers (LXC) before 2016-02-22. When executing a program via lxc-attach, the nonpriv session can escape to the parent session by using the TIOCSTI ioctl to push characters into the terminal's input buffer, allowing an attacker to escape the container.
{
"binaries": [
{
"binary_name": "liblxc1",
"binary_version": "1.0.10-0ubuntu1.1"
},
{
"binary_name": "lxc",
"binary_version": "1.0.10-0ubuntu1.1"
},
{
"binary_name": "lxc-dev",
"binary_version": "1.0.10-0ubuntu1.1"
},
{
"binary_name": "lxc-templates",
"binary_version": "1.0.10-0ubuntu1.1"
},
{
"binary_name": "lxc-tests",
"binary_version": "1.0.10-0ubuntu1.1"
},
{
"binary_name": "python3-lxc",
"binary_version": "1.0.10-0ubuntu1.1"
}
],
"availability": "No subscription required"
}