CVE-2024-28085
Summary
| CVE | CVE-2024-28085 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2024-03-27 19:15:48 UTC |
| Updated | 2026-05-12 12:16:33 UTC |
| Description | wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape sequences to be sent to other users' terminals through argv. (Specifically, escape sequences received from stdin are blocked, but escape sequences received from argv are not blocked.) There may be plausible scenarios where this leads to account takeover. |
Risk And Classification
Primary CVSS: v3.1 3.3 LOW from ADP
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
EPSS: 0.101770000 probability, percentile 0.931900000 (date 2026-05-12)
Problem Types: CWE-150 | n/a | CWE-150 CWE-150 Improper Neutralization of Escape, Meta, or Control Sequences
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | ADP | DECLARED | 3.3 | LOW | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
| 3.1 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | Secondary | 3.3 | LOW | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
LowAvailability
NoneCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 10.0 | All | All | All |
| Application | Kernel | Util-linux | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Na | N/a | affected n/a | Not specified |
| ADP | Kernel | Util-linux | affected 2.40 custom | Not specified |
| ADP | Siemens | SIMATIC S7-1500 CPU 1518-4 PN/DP MFP | affected V3.1.5 * custom | Not specified |
| ADP | Siemens | SIMATIC S7-1500 CPU 1518-4 PN/DP MFP | affected V3.1.5 * custom | Not specified |
| ADP | Siemens | SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP | affected V3.1.5 * custom | Not specified |
| ADP | Siemens | SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP | affected V3.1.5 * custom | Not specified |
| ADP | Siemens | SIPLUS S7-1500 CPU 1518-4 PN/DP MFP | affected V3.1.5 * custom | Not specified |
| ADP | Siemens | RUGGEDCOM ROX MX5000 | affected V2.17.0 custom | Not specified |
| ADP | Siemens | RUGGEDCOM ROX MX5000RE | affected V2.17.0 custom | Not specified |
| ADP | Siemens | RUGGEDCOM ROX RX1400 | affected V2.17.0 custom | Not specified |
| ADP | Siemens | RUGGEDCOM ROX RX1500 | affected V2.17.0 custom | Not specified |
| ADP | Siemens | RUGGEDCOM ROX RX1501 | affected V2.17.0 custom | Not specified |
| ADP | Siemens | RUGGEDCOM ROX RX1510 | affected V2.17.0 custom | Not specified |
| ADP | Siemens | RUGGEDCOM ROX RX1511 | affected V2.17.0 custom | Not specified |
| ADP | Siemens | RUGGEDCOM ROX RX1512 | affected V2.17.0 custom | Not specified |
| ADP | Siemens | RUGGEDCOM ROX RX1524 | affected V2.17.0 custom | Not specified |
| ADP | Siemens | RUGGEDCOM ROX RX1536 | affected V2.17.0 custom | Not specified |
| ADP | Siemens | RUGGEDCOM ROX RX5000 | affected V2.17.0 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.openwall.com/lists/oss-security/2024/03/27/6 | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Mailing List, Third Party Advisory |
| www.openwall.com/lists/oss-security/2024/03/27/7 | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Mailing List, Patch, Third Party Advisory |
| cert-portal.siemens.com/productcert/html/ssa-082556.html | 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e | cert-portal.siemens.com | |
| www.openwall.com/lists/oss-security/2024/03/27/5 | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Exploit, Mailing List, Third Party Advisory |
| www.openwall.com/lists/oss-security/2024/03/28/1 | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Mailing List, Patch, Third Party Advisory |
| Index of /pub/linux/utils/util-linux/ | af854a3a-2127-422b-91ae-364da2661108 | mirrors.edge.kernel.org | Product |
| www.openwall.com/lists/oss-security/2024/03/28/3 | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Mailing List, Patch, Third Party Advisory |
| www.openwall.com/lists/oss-security/2024/03/28/2 | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Mailing List, Third Party Advisory |
| cert-portal.siemens.com/productcert/html/ssa-202008.html | 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e | cert-portal.siemens.com | |
| lists.debian.org/debian-lts-announce/2024/04/msg00005.html | af854a3a-2127-422b-91ae-364da2661108 | lists.debian.org | Mailing List, Third Party Advisory |
| seclists.org/fulldisclosure/2024/Mar/35 | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | |
| security.netapp.com/advisory/ntap-20240531-0003 | af854a3a-2127-422b-91ae-364da2661108 | security.netapp.com | Third Party Advisory |
| oss-security - CVE-2024-28085: Escape sequence injection in util-linux wall | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Mailing List, Third Party Advisory |
| GitHub - skyler-ferrante/CVE-2024-28085: WallEscape vulnerability in util-linux | af854a3a-2127-422b-91ae-364da2661108 | github.com | Exploit, Third Party Advisory |
| www.openwall.com/lists/oss-security/2024/03/27/9 | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Mailing List, Patch, Third Party Advisory |
| github.com/util-linux/util-linux/security/advisories/GHSA-xv2h-c6ww-mrjq | af854a3a-2127-422b-91ae-364da2661108 | github.com | Broken Link |
| www.openwall.com/lists/oss-security/2024/03/27/8 | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Mailing List, Patch, Third Party Advisory |
| people.rit.edu/sjf5462/6831711781/wall_2_27_2024.txt | af854a3a-2127-422b-91ae-364da2661108 | people.rit.edu | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 200232 Ubuntu Security Notification for util-linux Vulnerability (USN-6719-1)
- 200246 Ubuntu Security Notification for util-linux Vulnerability (USN-6719-2)
- 6000550 Debian Security Update for util-linux (DSA 5650-1)
- 6000560 Debian Security Update for util-linux (DLA 3782-1)
- 756048 SUSE Enterprise Linux Security Update for util-linux (SUSE-SU-2024:1106-1)
- 756093 SUSE Enterprise Linux Security Update for util-linux (SUSE-SU-2024:1172-1)
- 756094 SUSE Enterprise Linux Security Update for util-linux (SUSE-SU-2024:1171-1)
- 756095 SUSE Enterprise Linux Security Update for util-linux (SUSE-SU-2024:1170-1)
- 756096 SUSE Enterprise Linux Security Update for util-linux (SUSE-SU-2024:1169-1)