runuser in util-linux allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer. http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-2779