diff --git a/meta/recipes-core/util-linux/util-linux.inc b/meta/recipes-core/util-linux/util-linux.inc
index 4b889927c80..6598a92b30f 100644
--- a/meta/recipes-core/util-linux/util-linux.inc
+++ b/meta/recipes-core/util-linux/util-linux.inc
@@ -56,6 +56,7 @@ SRC_URI = "${KERNELORG_MIRROR}/linux/utils/util-linux/v${MAJOR_VERSION}/util-lin
            file://0001-lib-fileutils-fix-RESOLVE_NO_SYMLINKS-fallback-value.patch \
            file://CVE-2026-53613.patch \
            file://CVE-2026-53612.patch \
+           file://CVE-2024-28085-0003.patch \
            "
 
 SRC_URI[sha256sum] = "7b6605e48d1a49f43cc4b4cfc59f313d0dd5402fa40b96810bd572e167dfed0f"
diff --git a/meta/recipes-core/util-linux/util-linux/CVE-2024-28085-0003.patch b/meta/recipes-core/util-linux/util-linux/CVE-2024-28085-0003.patch
new file mode 100644
index 00000000000..63d09ef4a1b
--- /dev/null
+++ b/meta/recipes-core/util-linux/util-linux/CVE-2024-28085-0003.patch
@@ -0,0 +1,77 @@
+From 61b49b7160bbb6780279344574746617e7fb11a4 Mon Sep 17 00:00:00 2001
+From: Karel Zak <kzak@redhat.com>
+Date: Mon, 24 Aug 2026 16:37:28 +0200
+Subject: [PATCH] wall, write: sanitize hostname in banner header
+
+The CVE-2024-28085 fix sanitized only message bodies via
+fputs_careful(), but the banner headers in wall(1) and write(1)
+still interpolate the system hostname without sanitization.
+
+An unprivileged user can set a malicious hostname containing
+terminal escape sequences via a user namespace (unshare -Ur -u
++ sethostname(2)), and wall/write will deliver those sequences
+to the terminals of all logged-in users.
+
+Fix by routing the banner output through fputs_careful() which
+strips control characters.
+
+This is an additional fix for CVE-2024-28085 (CVSS 3.1 score: 3.3).
+A new CVE ID has not been assigned (yet).
+
+Reported-by: Skyler Ferrante <sjf5462@rit.edu>
+Signed-off-by: Karel Zak <kzak@redhat.com>
+(cherry picked from commit 9ce8f2b5aefa011ef5b0c34aa14df9bb9db02dab)
+(cherry picked from commit f358b098d47659837d85b66fb387201224b272a0)
+
+CVE: CVE-2024-28085
+Upstream-Status: Backport [https://github.com/util-linux/util-linux/commit/61b49b7160bbb6780279344574746617e7fb11a4]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ term-utils/wall.c  | 3 ++-
+ term-utils/write.c | 6 ++++--
+ 2 files changed, 6 insertions(+), 3 deletions(-)
+
+diff --git a/term-utils/wall.c b/term-utils/wall.c
+index 7a4a858f5..c1c47d531 100644
+--- a/term-utils/wall.c
++++ b/term-utils/wall.c
+@@ -316,7 +316,8 @@ static char *makemsg(char *fname, char **mvec, int mvecsz,
+ 		snprintf(lbuf, lbuflen,
+ 				_("Broadcast message from %s@%s (%s) (%s):"),
+ 				whom, hostname, where, date);
+-		fprintf(fs, "%-*.*s\007\007\r\n", TERM_WIDTH, TERM_WIDTH, lbuf);
++		fputs_careful(lbuf, fs, '^', true, TERM_WIDTH);
++		fprintf(fs, "\007\007\r\n");
+ 		free(hostname);
+ 	}
+ 	fprintf(fs, "%*s\r\n", TERM_WIDTH, " ");
+diff --git a/term-utils/write.c b/term-utils/write.c
+index 3784f0300..d680d7464 100644
+--- a/term-utils/write.c
++++ b/term-utils/write.c
+@@ -233,6 +233,7 @@ static void do_write(const struct write_control *ctl)
+ 	time_t now;
+ 	struct tm *tm;
+ 	char *host, *line = NULL;
++	char buf[512];
+ 	size_t linelen = 0;
+ 	struct sigaction sigact;
+ 
+@@ -262,14 +263,15 @@ static void do_write(const struct write_control *ctl)
+ 	/* print greeting */
+ 	printf("\r\n\a\a\a");
+ 	if (strcmp(login, pwuid) != 0)
+-		printf(_("Message from %s@%s (as %s) on %s at %02d:%02d ..."),
++		snprintf(buf, sizeof(buf), _("Message from %s@%s (as %s) on %s at %02d:%02d ..."),
+ 		       login, host, pwuid, ctl->src_tty_name,
+ 		       tm->tm_hour, tm->tm_min);
+ 	else
+-		printf(_("Message from %s@%s on %s at %02d:%02d ..."),
++		snprintf(buf, sizeof(buf), _("Message from %s@%s on %s at %02d:%02d ..."),
+ 		       login, host, ctl->src_tty_name,
+ 		       tm->tm_hour, tm->tm_min);
+ 	free(host);
++	fputs_careful(buf, stdout, '^', true, 0);
+ 	printf("\r\n");
+ 
+ 	while (getline(&line, &linelen, stdin) >= 0) {
