CVE-2024-28085
published 2024-03-27CVE-2024-28085: wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape sequences to be sent to other users' terminals through argv…
PriorityP417low3.3CVSS 3.1
AVLACLPRLUINSUCNILAN
EPSS
2.24%
80.9th percentile
wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape sequences to be sent to other users' terminals through argv. (Specifically, escape sequences received from stdin are blocked, but escape sequences received from argv are not blocked.) There may be plausible scenarios where this leads to account takeover.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | util-linux | < util-linux 2.38.1-5+deb12u1 (bookworm) | util-linux 2.38.1-5+deb12u1 (bookworm) |
| kernel | util-linux | >= 0 < 2.36.1-8+deb11u2 | 2.36.1-8+deb11u2 |
| kernel | util-linux | >= 0 < 2.38.1-5+deb12u1 | 2.38.1-5+deb12u1 |
| kernel | util-linux | >= 0 < 2.39.3-11 | 2.39.3-11 |
| kernel | util-linux | >= 0 < 2.39.3-11 | 2.39.3-11 |
| kernel | util-linux | >= 2.24 < 2.39.4 | 2.39.4 |
| msrc | azl3_util-linux_2.39.2-2_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_util-linux_2.37.4-9_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
CVSS provenance
nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
osv3.3LOW
vendor_debian3.3LOW
vendor_msrc3.3LOW
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-px7f-qj7m-m4v6: wall in util-linux through 2
ghsa_unreviewed·2024-03-27
CVE-2024-28085 [LOW] CWE-150 GHSA-px7f-qj7m-m4v6: wall in util-linux through 2
wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape sequences to be sent to other users' terminals through argv. (Specifically, escape sequences received from stdin are blocked, but escape sequences received from argv are not blocked.) There may be plausible scenarios where this leads to account takeover.
OSV
CVE-2024-28085: wall in util-linux through 2
osv·2024-03-27·CVSS 3.3
CVE-2024-28085 [LOW] CVE-2024-28085: wall in util-linux through 2
wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape sequences to be sent to other users' terminals through argv. (Specifically, escape sequences received from stdin are blocked, but escape sequences received from argv are not blocked.) There may be plausible scenarios where this leads to account takeover.
CISA ICS
Siemens SIMATIC S7-1500 CPU Family
cisa_ics·2025-06-12
Siemens SIMATIC S7-1500 CPU Family
ICS Advisory
##
Siemens SIMATIC S7-1500 CPU Family
Release DateJune 12, 2025
Alert CodeICSA-25-162-05
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 8.7
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 CPU family
- Vulnerabilities: Missing Encryption of Sensitive Data, Out-of-bounds Read, Use After Free, Stack-
Ubuntu
util-linux vulnerability
vendor_ubuntu·2024-04-10
CVE-2024-28085 util-linux vulnerability
Title: util-linux vulnerability
Summary: util-linux could be made to expose sensitive information.
USN-6719-1 fixed a vulnerability in util-linux. Unfortunately, it was
discovered that the fix did not fully address the issue. This update
removes the setgid permission bit from the wall and write utilities.
Original advisory details:
Skyler Ferrante discovered that the util-linux wall command did not filter
escape sequences from command line arguments. A local attacker could
possibly use this issue to obtain sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
util-linux vulnerability
vendor_ubuntu·2024-03-27
CVE-2024-28085 util-linux vulnerability
Title: util-linux vulnerability
Summary: util-linux could be made to expose sensitive information.
Skyler Ferrante discovered that the util-linux wall command did not filter
escape sequences from command line arguments. A local attacker could
possibly use this issue to obtain sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
util-linux: CVE-2024-28085: wall: escape sequence injection
vendor_redhat·2024-03-27·CVSS 3.3
CVE-2024-28085 [LOW] CWE-268 util-linux: CVE-2024-28085: wall: escape sequence injection
util-linux: CVE-2024-28085: wall: escape sequence injection
wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape sequences to be sent to other users' terminals through argv. (Specifically, escape sequences received from stdin are blocked, but escape sequences received from argv are not blocked.) There may be plausible scenarios where this leads to account takeover.
An privilege chaining vulnerability was discovered in the util-linux package. A local, authenticated attacker could use mesg or wall to takeover another user's account.
Statement: This vulnerability doesn't affect any supported Red Hat products. The mesg and wall programs are installed without setgid permissions, which prevents exploitation.
Package: util-linux (Red Hat Enterprise Linux
Microsoft
wall in util-linux through 2.40 often installed with setgid tty permissions allows escape sequences to be sent to other users' terminals through argv. (Specifically escape sequences received from stdi
vendor_msrc·2024-03-12·CVSS 3.3
CVE-2024-28085 [LOW] CWE-150 wall in util-linux through 2.40 often installed with setgid tty permissions allows escape sequences to be sent to other users' terminals through argv. (Specifically escape sequences received from stdi
wall in util-linux through 2.40 often installed with setgid tty permissions allows escape sequences to be sent to other users' terminals through argv. (Specifically escape sequences received from stdin are blocked but escape sequences received from argv are not blocked.) There may be plausible scenarios where this leads to account takeover.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began pu
Debian
CVE-2024-28085: util-linux - wall in util-linux through 2.40, often installed with setgid tty permissions, al...
vendor_debian·2024·CVSS 3.3
CVE-2024-28085 [LOW] CVE-2024-28085: util-linux - wall in util-linux through 2.40, often installed with setgid tty permissions, al...
wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape sequences to be sent to other users' terminals through argv. (Specifically, escape sequences received from stdin are blocked, but escape sequences received from argv are not blocked.) There may be plausible scenarios where this leads to account takeover.
Scope: local
bookworm: resolved (fixed in 2.38.1-5+deb12u1)
bullseye: resolved (fixed in 2.36.1-8+deb11u2)
forky: resolved (fixed in 2.39.3-11)
sid: resolved (fixed in 2.39.3-11)
trixie: resolved (fixed in 2.39.3-11)
No detection rules found.
No public exploits indexed.
Bleepingcomputer
Decade-old Linux ‘wall’ bug helps make fake SUDO prompts, steal passwords
blogs_bleepingcomputer·2024-03-28
Decade-old Linux ‘wall’ bug helps make fake SUDO prompts, steal passwords
## Decade-old Linux ‘wall’ bug helps make fake SUDO prompts, steal passwords
## Bill Toulas
An attacker needs to have access to a Linux server that already has multiple users connected at the same time through the terminal, such as a college where students may connect for an assignment.
Security researcher Skyler Ferrante discovered WallEscape, which is described as an "improper neutralization of escape sequences in wall " command.
## Exploiting WallEscape
WallEscape impacts the ‘wall’ command, which is typically used in Linux systems to broadcast messages to the terminals of all users logged to the same system, such as a server.
Because escape sequences are improperly filtered when processing input through command line arguments, an unprivileged user could exploit the vulnerability
arXiv
KnowHow: Automatically Applying High-Level CTI Knowledge for Interpretable and Accurate Provenance Analysis
arxiv_fulltext·2025-09-06
KnowHow: Automatically Applying High-Level CTI Knowledge for Interpretable and Accurate Provenance Analysis
KnowHow: Automatically Applying High-Level CTI Knowledge for Interpretable and Accurate Provenance Analysis
Yuhan Meng2,
Shaofei Li2,
Jiaping Gui3,
Peng Jiang4,
and Ding Li* is the corresponding author.21
2Key Laboratory of High-Confidence Software Technologies (MOE), School of Computer Science, Peking University
3School of Computer Science, Shanghai Jiao Tong University, 4Southeast University
2\mengyuhan, lishaofei, ding_li\@pku.edu.cn, [email protected], [email protected]
\@IEEEpubidpullup6.5
Network and Distributed System Security (NDSS) Symposium 2026
23 - 27 February 2026 , San Diego, CA, USA
ISBN 979-8-9919276-8-0
https://dx.doi.org/10.14722/yyy.2026.[23|24]xxx
www.ndss-symposium.org
[ ]
\@IEEEpubidpullup6.5
Network and Distributed System Security (NDSS) Symposium 2026
http://www.openwall.com/lists/oss-security/2024/03/27/5http://www.openwall.com/lists/oss-security/2024/03/27/6http://www.openwall.com/lists/oss-security/2024/03/27/7http://www.openwall.com/lists/oss-security/2024/03/27/8http://www.openwall.com/lists/oss-security/2024/03/27/9http://www.openwall.com/lists/oss-security/2024/03/28/1http://www.openwall.com/lists/oss-security/2024/03/28/2http://www.openwall.com/lists/oss-security/2024/03/28/3https://github.com/skyler-ferrante/CVE-2024-28085https://github.com/util-linux/util-linux/security/advisories/GHSA-xv2h-c6ww-mrjqhttps://lists.debian.org/debian-lts-announce/2024/04/msg00005.htmlhttps://mirrors.edge.kernel.org/pub/linux/utils/util-linux/https://people.rit.edu/sjf5462/6831711781/wall_2_27_2024.txthttps://security.netapp.com/advisory/ntap-20240531-0003/https://www.openwall.com/lists/oss-security/2024/03/27/5http://seclists.org/fulldisclosure/2024/Mar/35http://www.openwall.com/lists/oss-security/2024/03/27/5http://www.openwall.com/lists/oss-security/2024/03/27/6http://www.openwall.com/lists/oss-security/2024/03/27/7http://www.openwall.com/lists/oss-security/2024/03/27/8http://www.openwall.com/lists/oss-security/2024/03/27/9http://www.openwall.com/lists/oss-security/2024/03/28/1http://www.openwall.com/lists/oss-security/2024/03/28/2http://www.openwall.com/lists/oss-security/2024/03/28/3https://github.com/skyler-ferrante/CVE-2024-28085https://github.com/util-linux/util-linux/security/advisories/GHSA-xv2h-c6ww-mrjqhttps://lists.debian.org/debian-lts-announce/2024/04/msg00005.htmlhttps://mirrors.edge.kernel.org/pub/linux/utils/util-linux/https://people.rit.edu/sjf5462/6831711781/wall_2_27_2024.txthttps://security.netapp.com/advisory/ntap-20240531-0003/https://www.openwall.com/lists/oss-security/2024/03/27/5https://cert-portal.siemens.com/productcert/html/ssa-082556.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-202008.html
2024-03-27
Published