chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer. http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-2781