cbcvebase.
CVE-2024-28085
published 2024-03-27

CVE-2024-28085: wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape sequences to be sent to other users' terminals through argv…

PriorityP417low3.3CVSS 3.1
AVLACLPRLUINSUCNILAN
EPSS
2.24%
80.9th percentile
wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape sequences to be sent to other users' terminals through argv. (Specifically, escape sequences received from stdin are blocked, but escape sequences received from argv are not blocked.) There may be plausible scenarios where this leads to account takeover.

Affected

13 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianutil-linux< util-linux 2.38.1-5+deb12u1 (bookworm)util-linux 2.38.1-5+deb12u1 (bookworm)
kernelutil-linux>= 0 < 2.36.1-8+deb11u22.36.1-8+deb11u2
kernelutil-linux>= 0 < 2.38.1-5+deb12u12.38.1-5+deb12u1
kernelutil-linux>= 0 < 2.39.3-112.39.3-11
kernelutil-linux>= 0 < 2.39.3-112.39.3-11
kernelutil-linux>= 2.24 < 2.39.42.39.4
msrcazl3_util-linux_2.39.2-2_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl2_util-linux_2.37.4-9_on_cbl_mariner_2.0
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64

CVSS provenance

nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
osv3.3LOW
vendor_debian3.3LOW
vendor_msrc3.3LOW
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.