CVE-2024-28085: Escape sequence injection in util-linux wall

Published Mar 27, 2024
·
Updated

wall in util-linux through 2.40 often installed with setgid tty permissions allows escape sequences to be sent to other users' terminals through argv. (Specifically escape sequences received from stdin are blocked but escape sequences received from argv are not blocked.) There may be plausible scenarios where this leads to account takeover.

Other sources

wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape sequences to be sent to other users' terminals through argv. (Specifically, escape sequences received from stdin are blocked, but escape sequences received from argv are not blocked.) There may be plausible scenarios where this leads to account takeover.

Ubuntu

Affected Software

9 affected componentsFixes available
ubuntu/util-linux<2.34-0.1ubuntu9.5
2.34-0.1ubuntu9.5
ubuntu/util-linux<2.37.2-4ubuntu3.3
2.37.2-4ubuntu3.3
ubuntu/util-linux<2.39.1-4ubuntu2.1
2.39.1-4ubuntu2.1
ubuntu/util-linux<2.39.3-9ubuntu6
2.39.3-9ubuntu6
debian/util-linux<=2.33.1-0.1, <=2.36.1-8+deb11u1, <=2.38.1-5
2.33.1-0.1+deb10u12.36.1-8+deb11u22.38.1-5+deb12u12.40-8
kernel util-linux>=2.24<2.39.4
Debian Debian Linux=10.0
Microsoft cbl2 util-linux 2.37.4-9
Microsoft azl3 util-linux 2.39.2-2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade ubuntu/util-linux to a version that resolves this vulnerability.

    Fixed in 2.34-0.1ubuntu9.5
  2. Upgrade

    Upgrade ubuntu/util-linux to a version that resolves this vulnerability.

    Fixed in 2.37.2-4ubuntu3.3
  3. Upgrade

    Upgrade ubuntu/util-linux to a version that resolves this vulnerability.

    Fixed in 2.39.1-4ubuntu2.1
  4. Upgrade

    Upgrade ubuntu/util-linux to a version that resolves this vulnerability.

    Fixed in 2.39.3-9ubuntu6
  5. Upgrade

    Upgrade debian/util-linux to a version that resolves this vulnerability.

    Fixed in 2.33.1-0.1+deb10u1Fixed in 2.36.1-8+deb11u2Fixed in 2.38.1-5+deb12u1Fixed in 2.40-8

Event History

Mar 27, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
Description
Data Sourced
via NVD·07:15 PM
RemedySeverityWeaknessAffected Software
Mar 28, 2024
News Published
via BleepingComputer·09:03 PM
News Published
via BleepingComputer·09:05 PM
Apr 1, 2024
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
DescriptionSeverity
May 2, 2024
Data Sourced
via Launchpad·05:43 PM
Description

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-28085?

CVE-2024-28085 is classified as a vulnerability that can allow unauthorized escape sequences to affect other users' terminals.

2

How do I fix CVE-2024-28085?

To mitigate CVE-2024-28085, you should update the util-linux package to a version beyond the specified vulnerable versions listed in the advisory.

3

Which versions of util-linux are affected by CVE-2024-28085?

CVE-2024-28085 affects util-linux versions before 2.40, specifically those installed with setgid tty permissions.

4

What systems are impacted by CVE-2024-28085?

CVE-2024-28085 impacts systems running vulnerable versions of util-linux on Ubuntu and Debian distributions.

5

Can CVE-2024-28085 lead to password theft?

Yes, CVE-2024-28085 can potentially allow an attacker to create fake sudo prompts, leading to password theft.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203