{"id":"CVE-2024-28085","details":"wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape sequences to be sent to other users' terminals through argv. (Specifically, escape sequences received from stdin are blocked, but escape sequences received from argv are not blocked.) There may be plausible scenarios where this leads to account takeover.","aliases":["GHSA-xv2h-c6ww-mrjq"],"modified":"2026-08-12T03:51:48.156987269Z","published":"2024-03-27T00:00:00Z","related":["SUSE-SU-2024:1106-1","SUSE-SU-2024:1169-1","SUSE-SU-2024:1170-1","SUSE-SU-2024:1171-1","SUSE-SU-2024:1172-1","SUSE-SU-2024:1943-1","SUSE-SU-2025:20003-1","SUSE-SU-2025:20304-1","openSUSE-SU-2024:14523-1"],"database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/28xxx/CVE-2024-28085.json"},"references":[{"type":"WEB","url":"http://seclists.org/fulldisclosure/2024/Mar/35"},{"type":"WEB","url":"https://cert-portal.siemens.com/productcert/html/ssa-082556.html"},{"type":"WEB","url":"https://cert-portal.siemens.com/productcert/html/ssa-202008.html"},{"type":"WEB","url":"https://mirrors.edge.kernel.org/pub/linux/utils/util-linux/"},{"type":"WEB","url":"https://people.rit.edu/sjf5462/6831711781/wall_2_27_2024.txt"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2024/03/27/5"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/28xxx/CVE-2024-28085.json"},{"type":"ADVISORY","url":"https://github.com/util-linux/util-linux/security/advisories/GHSA-xv2h-c6ww-mrjq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-28085"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20240531-0003/"},{"type":"PACKAGE","url":"https://github.com/skyler-ferrante/CVE-2024-28085"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2024/03/27/5"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2024/03/27/6"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2024/03/27/7"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2024/03/27/8"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2024/03/27/9"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2024/03/28/1"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2024/03/28/2"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2024/03/28/3"},{"type":"ARTICLE","url":"https://lists.debian.org/debian-lts-announce/2024/04/msg00005.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/util-linux/util-linux","events":[{"introduced":"bad3c52f0b2dd97e70a5c92edcc7f67dceeb4ba1"},{"fixed":"c1c1ab8b8e67e04ee293d4cf5679430a5b174bb8"}],"database_specific":{"cpe":"cpe:2.3:a:kernel:util-linux:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"2.40"},{"introduced":"2.24"},{"fixed":"2.39.4"}],"source":["DESCRIPTION","CPE_RANGE"]}}],"versions":["v2.40-rc2","v2.41-start","v2.41-devel","v2.40-rc1","v2.39","v2.39-rc3","v2.39-rc2","v2.39-rc1","v2.38","v2.38-rc4","v2.38-rc3","v2.38-rc2","v2.38-rc1","v2.37","v2.37-rc2","v2.37-rc1","v2.36","v2.36-rc2","v2.36-rc1","v2.35","v2.35-rc2","v2.35-rc1","v2.34","v2.34-rc2","v2.34-rc1","v2.33","v2.33-rc2","v2.33-rc1","v2.32","v2.32-rc2","v2.32-rc1","v2.31","v2.31-rc2","v2.31-rc1","v2.30","v2.30-rc2","v2.30-rc1","v2.29","v2.29-rc2","v2.29-rc1","v2.28","v2.28-rc2","v2.28-rc1","v2.27","v2.27-rc2","v2.27-rc1","v2.26","v2.26-rc2","v2.26-rc1","v2.25","v2.25-rc2","v2.25-rc1","v2.24"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-28085.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"}]}