Launchpad.net

CVE 2016-2568

pkexec, when used with --user nonpriv, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer.

See the CVE page on Mitre.org for more details.