SELinux policycoreutils allows local users to execute arbitrary commands outside of the sandbox via a crafted TIOCSTI ioctl call.
No PoCs from references.
- https://github.com/ARPSyndicate/cvemon
- https://github.com/enterprisemodules/vulnerability_demo
- https://github.com/hartwork/antijack