CVE-2024-28085

WallEscape: escape sequences in a broadcast message, painting a fake password prompt

The wall command broadcasts a message to everyone logged in. It did not strip terminal escape sequences, so an unprivileged user could draw convincing fake prompts on other people's terminals.

util-linuxNot in CISA’s Known Exploited catalogueEPSS 2.2% chance of an attempt in 30 daysCVSS 3.3CWE-150CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

A fixed package version is available on 4 of the releases below. Each row names the version, and the section below it says when this does not apply to you at all.

One read-only command. No account, no agent, nothing changed.

What it actually is

wall is installed setgid tty so it can write to other users' terminals. It passed a message through without filtering escape sequences, which means the sender controls what appears on the recipient's screen, including where the cursor goes and what is echoed.

What an attacker gets: A credible fake sudo password prompt on another user's terminal, and their password typed into it. Also a way to alter what a terminal displays, which matters if somebody is reading output they intend to act on.

When it applies to you, and when it does not

An old package version and a real exposure are different things. These are the conditions this one needs.

  • It needs other users logged in on terminals for the message to reach. A single-administrator server with one session has nobody to deceive.
  • It needs message reception enabled, which `mesg n` turns off per user.
  • This is a social engineering primitive rather than a memory bug, and it is a good reminder that what a terminal shows is not evidence of what produced it.

Check your own server

Read-only, changes nothing
ls -l /usr/bin/wall && who

Shows whether wall is setgid tty and who is currently logged in to be targeted.

Fixed package version, per distribution

From each distribution’s own advisory data, asked per release. A version here is the package version that carries the fix on that release, not the upstream release number.

ReleaseSource packageStateFixed in
Ubuntu 22.04 LTSutil-linuxFixed2.37.2-4ubuntu3.4
Ubuntu 24.04 LTSutil-linuxFixed2.39.3-9ubuntu6
Debian 12 (bookworm)util-linuxFixed2.38.1-5+deb12u1
Debian 13 (trixie)util-linuxFixed2.39.3-11
Rocky Linux 9util-linuxNo advisory names itno advisory for this release names it
AlmaLinux 9util-linuxNo advisory names itno advisory for this release names it

Install the fix with apt update && apt install --only-upgrade util-linux on Debian and Ubuntu, or dnf update util-linux on Rocky Linux and AlmaLinux. Restart whatever was using it afterwards: a patched file on disk is not a patched process in memory.

What SecAI has recorded about it

wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape sequences to be sent to other users' terminals through argv. (Specifically, escape sequences received from stdin are blocked, but escape sequences received from argv are not blocked.) There may be plausible scenarios where this leads to account takeover.

Recorded from nvd. Its weakness class is CWE-150, from NVD.

Read next

Check whether this vulnerability affects your Linux server

One read-only command, no account and no agent. It reads the installed package versions on your server and tells you which advisories apply to them, CVE-2024-28085 included. It changes nothing.