WallEscape: escape sequences in a broadcast message, painting a fake password prompt
The wall command broadcasts a message to everyone logged in. It did not strip terminal escape sequences, so an unprivileged user could draw convincing fake prompts on other people's terminals.
A fixed package version is available on 4 of the releases below. Each row names the version, and the section below it says when this does not apply to you at all.
What it actually is
wall is installed setgid tty so it can write to other users' terminals. It passed a message through without filtering escape sequences, which means the sender controls what appears on the recipient's screen, including where the cursor goes and what is echoed.
What an attacker gets: A credible fake sudo password prompt on another user's terminal, and their password typed into it. Also a way to alter what a terminal displays, which matters if somebody is reading output they intend to act on.
When it applies to you, and when it does not
An old package version and a real exposure are different things. These are the conditions this one needs.
- It needs other users logged in on terminals for the message to reach. A single-administrator server with one session has nobody to deceive.
- It needs message reception enabled, which `mesg n` turns off per user.
- This is a social engineering primitive rather than a memory bug, and it is a good reminder that what a terminal shows is not evidence of what produced it.
Check your own server
ls -l /usr/bin/wall && whoShows whether wall is setgid tty and who is currently logged in to be targeted.
Fixed package version, per distribution
From each distribution’s own advisory data, asked per release. A version here is the package version that carries the fix on that release, not the upstream release number.
| Release | Source package | State | Fixed in |
|---|---|---|---|
| Ubuntu 22.04 LTS | util-linux | Fixed | 2.37.2-4ubuntu3.4 |
| Ubuntu 24.04 LTS | util-linux | Fixed | 2.39.3-9ubuntu6 |
| Debian 12 (bookworm) | util-linux | Fixed | 2.38.1-5+deb12u1 |
| Debian 13 (trixie) | util-linux | Fixed | 2.39.3-11 |
| Rocky Linux 9 | util-linux | No advisory names it | no advisory for this release names it |
| AlmaLinux 9 | util-linux | No advisory names it | no advisory for this release names it |
Install the fix with apt update && apt install --only-upgrade util-linux on Debian and Ubuntu, or dnf update util-linux on Rocky Linux and AlmaLinux. Restart whatever was using it afterwards: a patched file on disk is not a patched process in memory.
What SecAI has recorded about it
wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape sequences to be sent to other users' terminals through argv. (Specifically, escape sequences received from stdin are blocked, but escape sequences received from argv are not blocked.) There may be plausible scenarios where this leads to account takeover.
Recorded from nvd. Its weakness class is CWE-150, from NVD.
- http://www.openwall.com/lists/oss-security/2024/03/27/5
- http://www.openwall.com/lists/oss-security/2024/03/27/6
- http://www.openwall.com/lists/oss-security/2024/03/27/7
- http://www.openwall.com/lists/oss-security/2024/03/27/8
- http://www.openwall.com/lists/oss-security/2024/03/27/9
- http://www.openwall.com/lists/oss-security/2024/03/28/1
Read next
Check whether this vulnerability affects your Linux server
One read-only command, no account and no agent. It reads the installed package versions on your server and tells you which advisories apply to them, CVE-2024-28085 included. It changes nothing.