@@ -56,6 +56,7 @@ SRC_URI = "${KERNELORG_MIRROR}/linux/utils/util-linux/v${MAJOR_VERSION}/util-lin
file://0001-lib-fileutils-fix-RESOLVE_NO_SYMLINKS-fallback-value.patch \
file://CVE-2026-53613.patch \
file://CVE-2026-53612.patch \
+ file://CVE-2024-28085-0003.patch \
"
SRC_URI[sha256sum] = "7b6605e48d1a49f43cc4b4cfc59f313d0dd5402fa40b96810bd572e167dfed0f"
new file mode 100644
@@ -0,0 +1,77 @@
+From 61b49b7160bbb6780279344574746617e7fb11a4 Mon Sep 17 00:00:00 2001
+From: Karel Zak <kzak@redhat.com>
+Date: Mon, 24 Aug 2026 16:37:28 +0200
+Subject: [PATCH] wall, write: sanitize hostname in banner header
+
+The CVE-2024-28085 fix sanitized only message bodies via
+fputs_careful(), but the banner headers in wall(1) and write(1)
+still interpolate the system hostname without sanitization.
+
+An unprivileged user can set a malicious hostname containing
+terminal escape sequences via a user namespace (unshare -Ur -u
++ sethostname(2)), and wall/write will deliver those sequences
+to the terminals of all logged-in users.
+
+Fix by routing the banner output through fputs_careful() which
+strips control characters.
+
+This is an additional fix for CVE-2024-28085 (CVSS 3.1 score: 3.3).
+A new CVE ID has not been assigned (yet).
+
+Reported-by: Skyler Ferrante <sjf5462@rit.edu>
+Signed-off-by: Karel Zak <kzak@redhat.com>
+(cherry picked from commit 9ce8f2b5aefa011ef5b0c34aa14df9bb9db02dab)
+(cherry picked from commit f358b098d47659837d85b66fb387201224b272a0)
+
+CVE: CVE-2024-28085
+Upstream-Status: Backport [https://github.com/util-linux/util-linux/commit/61b49b7160bbb6780279344574746617e7fb11a4]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ term-utils/wall.c | 3 ++-
+ term-utils/write.c | 6 ++++--
+ 2 files changed, 6 insertions(+), 3 deletions(-)
+
+diff --git a/term-utils/wall.c b/term-utils/wall.c
+index 7a4a858f5..c1c47d531 100644
+--- a/term-utils/wall.c
++++ b/term-utils/wall.c
+@@ -316,7 +316,8 @@ static char *makemsg(char *fname, char **mvec, int mvecsz,
+ snprintf(lbuf, lbuflen,
+ _("Broadcast message from %s@%s (%s) (%s):"),
+ whom, hostname, where, date);
+- fprintf(fs, "%-*.*s\007\007\r\n", TERM_WIDTH, TERM_WIDTH, lbuf);
++ fputs_careful(lbuf, fs, '^', true, TERM_WIDTH);
++ fprintf(fs, "\007\007\r\n");
+ free(hostname);
+ }
+ fprintf(fs, "%*s\r\n", TERM_WIDTH, " ");
+diff --git a/term-utils/write.c b/term-utils/write.c
+index 3784f0300..d680d7464 100644
+--- a/term-utils/write.c
++++ b/term-utils/write.c
+@@ -233,6 +233,7 @@ static void do_write(const struct write_control *ctl)
+ time_t now;
+ struct tm *tm;
+ char *host, *line = NULL;
++ char buf[512];
+ size_t linelen = 0;
+ struct sigaction sigact;
+
+@@ -262,14 +263,15 @@ static void do_write(const struct write_control *ctl)
+ /* print greeting */
+ printf("\r\n\a\a\a");
+ if (strcmp(login, pwuid) != 0)
+- printf(_("Message from %s@%s (as %s) on %s at %02d:%02d ..."),
++ snprintf(buf, sizeof(buf), _("Message from %s@%s (as %s) on %s at %02d:%02d ..."),
+ login, host, pwuid, ctl->src_tty_name,
+ tm->tm_hour, tm->tm_min);
+ else
+- printf(_("Message from %s@%s on %s at %02d:%02d ..."),
++ snprintf(buf, sizeof(buf), _("Message from %s@%s on %s at %02d:%02d ..."),
+ login, host, ctl->src_tty_name,
+ tm->tm_hour, tm->tm_min);
+ free(host);
++ fputs_careful(buf, stdout, '^', true, 0);
+ printf("\r\n");
+
+ while (getline(&line, &linelen, stdin) >= 0) {