peter bassill · operator
$ cve CVE-2017-5226 JSON

CVE-2017-5226

10.0
CRITICAL · CVSS 3.0 · EPSS 3.2% (pctl 88)

In your normal cycle

Critical by CVSS (10), but no sign of active exploitation.

Description

When executing a program via the bubblewrap sandbox, the nonpriv session can escape to the parent session by using the TIOCSTI ioctl to push characters into the terminal's input buffer, allowing an attacker to escape the sandbox.

Scoring

CVSS10.0 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS3.17% — more likely to be exploited than 88% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploitnone known
Published2017-03-29
Last modified2026-06-17

Affected (1)

VendorProduct
projectatomicbubblewrap

References

→ the Explorer  ·  watch your stack  ·  NVD