← Vulnerability feed

Vulnerability record · CVE-2016-10124 · published 9 January 2017

CVE-2016-10124: Linuxcontainers lxc improper access control vulnerability

Linuxcontainers · Lxc

An issue was discovered in Linux Containers (LXC) before 2016-02-22. When executing a program via lxc-attach, the nonpriv session can escape to the parent session by using the TIOCSTI ioctl to push characters into the terminal's input buffer, allowing an attacker to escape the container.

8.6 CVSS 3.0 High EPSS 1.5% · top 26.2% CWE-284 · Improper access control
8.6CVSS 3.0 base score, v2 5.0
1.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References
17 Jun 2026Last modified by NVD

Description

An issue was discovered in Linux Containers (LXC) before 2016-02-22. When executing a program via lxc-attach, the nonpriv session can escape to the parent session by using the TIOCSTI ioctl to push characters into the terminal's input buffer, allowing an attacker to escape the container.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-10124 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2016-8649Linuxcontainers lxc permissions and access controls vulnerabilitylxc-attach in LXC before 1.0.9 and 2.x before 2.0.6 allows an attacker inside of an unprivileged container to use an inherited file descriptor, of th…EPSS 2.8%8.6CVE-2019-5736runc container escape via /proc/self/exe overwrite of host binaryrunc through 1.0-rc6, as used in Docker before 18.09.2 and other products, mishandles file descriptors related to /proc/self/exe, letting an attacker…EPSS 98%analysed8.1CVE-2017-18641Linuxcontainers lxc improper authentication vulnerabilityIn LXC 2.0, many template scripts download code over cleartext HTTP, and omit a digital-signature check, before running it to bootstrap containers.EPSS 1.4%7.2CVE-2015-1335Linuxcontainers lxc link following vulnerabilitylxc-start in lxc before 1.0.8 and 1.1.x before 1.1.4 allows local container administrators to escape AppArmor confinement via a symlink attack on a (…EPSS 0.46%7.2CVE-2013-6441Linuxcontainers lxc permissions and access controls vulnerabilityThe lxc-sshd template (templates/lxc-sshd.in) in LXC before 1.0.0.beta2 uses read-write permissions when mounting /sbin/init, which allows local user…EPSS 0.50%4.9CVE-2015-1331Linuxcontainers lxc link following vulnerabilitylxclock.c in LXC 1.1.2 and earlier allows local users to create arbitrary files via a symlink attack on /run/lock/lxc/*.EPSS 0.46%4.6CVE-2015-1334Linuxcontainers lxc vulnerabilityattach.c in LXC 1.1.2 and earlier uses the proc filesystem in a container, which allows local container users to escape AppArmor or SELinux confineme…EPSS 0.37%4.3CVE-2026-39402Linuxcontainers lxc incorrect authorization vulnerabilitylxc is a Linux container runtime. In the setuid helper lxc-user-nic, the delete path contains a logic flaw in the find_line() function that allows an…EPSS 0.14%

Source: NIST National Vulnerability Database (record CVE-2016-10124), CISA KEV, FIRST EPSS (scores of 2026-10-01). This page is refreshed as NVD updates the record.