Improper Neutralization of Special Elements in Output Used by a Downstream Component in Util-linux - #VU146719

 

Improper Neutralization of Special Elements in Output Used by a Downstream Component in Util-linux - #VU146719

Published: September 2, 2026


Vulnerability identifier: #VU146719
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-74
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to inject terminal escape sequences into other users\' terminals.

The vulnerability exists due to improper neutralization of special elements in output used by a downstream component in wall(1)/write(1) message headers when interpolating a hostname controlled from a UTS namespace. A local user can set a crafted hostname and invoke wall(1) or write(1) to inject terminal escape sequences into other users\' terminals.

Exploitation requires the ability to change the hostname in the attacker\'s own UTS namespace, and delivery depends on the target terminal accepting messages; write(1) additionally requires the target user to have messages enabled.


Affected software

Util-linux

Remediation

Install security update from vendor's website.

Util-linux - addressed in versions 2.41.6, 2.42.3

External References

Related Security Bulletins