Back

MEDIUM

util-linux: CVE-2024-28085: wall: escape sequence injection

Published Mar 27, 2024

Description

wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape sequences to be sent to other users' terminals through argv. (Specifically, escape sequences received from stdin are blocked, but escape sequences received from argv are not blocked.) There may be plausible scenarios where this leads to account takeover.

Affected products

Remediation

Red Hat statement

This vulnerability doesn't affect any supported Red Hat products. The mesg and wall programs are installed without setgid permissions, which prevents exploitation.

Weaknesses (2)

References (23)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner mitre
Published Mar 27, 2024
Updated Jul 14, 2026
Reserved Mar 3, 2024

CISA Vulnrichment

Updated Aug 26, 2024

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Low
Public date Mar 27, 2024
Bugzilla 2271942

ENISA EUVD

Assigner mitre
Published Mar 27, 2024
Updated Jul 14, 2026

GitHub

No data