Database/Kernel, userspace & hypervisor
util-linux (wall): WallEscape: escape-sequence injection via wall(1)
CVSS 4.4CVE-2024-28085Kernel, userspace & hypervisorcurated
Impact
WallEscape: escape-sequence injection via wall(1) - can spoof a sudo prompt and steal a password on a shared host
Who can reach it
Local user on a shared login/head node
What to do
Package update; no reboot. Only matters where multiple tenants share a login node
References
Related entries
- Linux kernel (drivers/pci/pcie): PCIe bandwidth control dereferences a bridge's subordinate bus pointer withoutCVE-2025-22031 · Linux kernel (drivers/pci/pcie)Medium
- Linux kernel (drivers/pci/endpoint/functions): The NTB endpoint function drivers never checked whether their workqueueCVE-2025-71313 · Linux kernel (drivers/pci/endpoint/functions)Medium
- QEMU: signed/unsigned mismatch in vhost inflight migration state overruns the mmap-backed regionCVE-2026-6426 · QEMU vhost inflight migration (VMS_VBUFFER destination size handling)Medium
- Xen: x86 PV guest keeps a stale TLB entry to a freed page and can write it after scrubbingCVE-2026-79603 · Xen hypervisor (x86 PV guest page free / TLB flush window)Medium
- Linux kernel (drivers/iommu/amd): The AMD-Vi PPR (peripheral page request) notifier looked up the faulting PCI deviceCVE-2022-50505 · Linux kernel (drivers/iommu/amd)Medium
- Linux kernel (net/tls): Tls_sw_recvmsg takes a psock reference before acquiring the reader lock and returns withoutCVE-2024-35908 · Linux kernel (net/tls)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.