A bug in the wall command of the util-linux package that is part of the Linux operating system ( WallEscape ) could allow an attacker to steal passwords or change the victim's clipboard.
See also: Magnet Goblin distributes Linux malware via 1-day flaws

Known as CVE-2024-28085, the bug has been dubbed WallEscape and has been found in every version of the util-linux for the past 11 years, up until version 2.40 , which was released yesterday.
While the vulnerability is an interesting example of how an attacker can trick a user into giving up their password, exploitation is likely limited to specific scenarios.
An attacker needs to have access to a Linux server that already has multiple users logged in simultaneously via the terminal, such as a school where students might be logging in for an assignment.
Security researcher Skyler Ferrante discovered the WallEscape flaw, which is described as “improper disabling of escape sequences in the wall Linux.”
The WallEscape bug affects the 'wall' command, which is commonly used on Linux systems to broadcast messages to the terminals of all users logged into the same system, such as a server.
Since escape sequences are incorrectly filtered when processing input via command-line arguments, an unauthorized user could exploit the vulnerability by using escape control characters to create a fake SUDO window on other users' terminals and trick them into typing their administrator password.
See also: ANY.RUN Sandbox: Allows SOC and DFIR teams to analyze advanced Linux malware

The flaw can be exploited under certain conditions. Ferrante explains that the exploit is possible if the “mesg” is enabled and the wall has permissions setgid.
The researcher notes that both conditions are provided in Ubuntu 22.04 LTS (Jammy Jellyfish) and Debian 12.5 (Bookworm), but not in CentOS.
The PoC for the WallEscape flaw in the Linux operating system has been published to show how an attacker could exploit the flaw. In addition to the technical details, Ferrante also includes exploitation scenarios that could lead to different outcomes.
An example describes the steps to create a fake sudo prompt for the Gnome to trick the user into typing in their password. Ferrante explains that this is possible by creating a fake SUDO window for the Gnome terminal to trick the user into typing in the sensitive information as a command line parameter.
It is important to note that the WallEscape exploit relies on local access (physical or remote via SSH), which limits its severity. The risk comes from unprivileged users accessing the same system as the victim in multi-user environments, such as an organization's server.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Linux: Critical vulnerability affects most distributions by introducing bootkits

How can someone protect their system from Linux vulnerabilities?
The first and most important step in protecting a Linux system from vulnerabilities like the WallEscape bug is to keep your system up to date. Most Linux distributions provide tools to automatically update your system and installed applications. It is also important to only use applications from trusted sources. This means that you should avoid installing software from untrusted sources or running files you receive from strangers. In addition, it is important to use an antivirus and firewall. Although Linux is less vulnerable to viruses than other operating systems, using these tools can provide additional protection. Finally, it is important to set your file permissions correctly.
Source: bleepingcomputer
