CVE-2024-28085

LOW

util-linux <2.40 - Privilege Escalation

Title source: llm

Description

wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape sequences to be sent to other users' terminals through argv. (Specifically, escape sequences received from stdin are blocked, but escape sequences received from argv are not blocked.) There may be plausible scenarios where this leads to account takeover.

Exploits (2)

nomisec WORKING POC 51 stars
by skyler-ferrante · poc
https://github.com/skyler-ferrante/CVE-2024-28085
nomisec BACKDOOR: TROJAN 2 stars
by oditynet · poc
https://github.com/oditynet/sleepall

Scores

CVSS v3 3.3
EPSS 0.1018
EPSS Percentile 93.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Details

CWE
CWE-150
Status published
Products (2)
debian/debian_linux 10.0
kernel/util-linux 2.24 - 2.39.4
Published Mar 27, 2024
Tracked Since Feb 18, 2026