yocto ▾
›
scarthgap ▾
›
vulnerability
›
CVE-2016-2568
Component Overview
Vulnerability Overview
Name
CVE-2016-2568
Source
NVD (
link
)
Debian (
link
)
Description
pkexec, when used with --user nonpriv, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer.
CWEs
CWE-116
Published Date
Feb 13, 2017
Updated Date
Jun 17, 2026
Workaround
-
Advisories
http://www.openwall.com/lists/oss-security/2016/02/26/3
Mailing List
https://access.redhat.com/security/cve/cve-2016-2568
Third Party Advisory
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=816062
Mailing List
https://bugzilla.redhat.com/show_bug.cgi?id=1300746
Issue Tracking
https://ubuntu.com/security/CVE-2016-2568
Third Party Advisory
http://www.openwall.com/lists/oss-security/2016/02/26/3
Mailing List
https://access.redhat.com/security/cve/cve-2016-2568
Third Party Advisory
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=816062
Mailing List
https://bugzilla.redhat.com/show_bug.cgi?id=1300746
Issue Tracking
https://ubuntu.com/security/CVE-2016-2568
Third Party Advisory
Analysis
#
Affected Component
Analysis
polkit
Exploitable
Vulnerability Ratings
#
7.8
CVSSv31
4.4
CVSSv2
Others affected components
#
Name
Project
Project Version
Version
Status
polkit
buildroot
2025.02.x
125
Exploitable
polkit
buildroot
master
126
Exploitable
polkit
yocto
kirkstone
0.119
Exploitable
polkit
yocto
master
127
Not Affected