logo

Decade-old Linux ‘wall’ bug helps make fake SUDO prompts, steal passwords

ID: c4db8496-4f76-5466-a406-0594821514e3

STIX ID: report--c4db8496-4f76-5466-a406-0594821514e3

Feed Name: Bleeping Computer

Threat Score
35/100

Date Published: 2024-03-28

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

**WallEscape (CVE-2024-28085)** — A vulnerability in the util-linux 'wall' command allows local unprivileged users on multi-user Linux systems to send escape sequences that can create fake sudo prompts or change a victim's clipboard; proof-of-concept exploit code exists and mitigations include updating to util-linux v2.40, removing setgid from wall, or disabling mesg.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.