← Back to browse · API

CVE-2023-1523

Severity
CRITICAL
CVSS
10.0
EPSS
0.01447
Risk score
40.51
CISA KEV
No
PoC
No
Published
2023-09-01
Modified
2024-10-01
First seen
2026-08-07
Aliases
EUVD-2023-23767, GHSA-55WX-23FJ-C2V5
Products
-
Sources
euvd EUVD-2023-23767

Description

Using the TIOCLINUX ioctl request, a malicious snap could inject contents into the input of the controlling terminal which could allow it to cause arbitrary commands to be executed outside of the snap sandbox after the snap exits. Graphical terminal emulators like xterm, gnome-terminal and others are not affected - this can only be exploited when snaps are run on a virtual console.

References