A public disclosure detailed that systemd-journald in systemd 259 fails to escape control characters in emergency-level messages forwarded with wall, allowing any local user to inject crafted escape sequences into other users’ terminals when ForwardToWall=yes and MaxWallLevel=emerg are enabled. The issue affects TTYs and some root-owned PTYs, letting attackers manipulate terminal output and potentially trigger unsafe behavior in terminal emulators that render the sequences.
Aaron Rainbolt showed that the flaw can be chained with XTerm behavior tied to CVE-2022-45063 to escalate privileges. In the demonstrated scenario, an unprivileged user sends a malicious emerg-level log message that reaches a root shell running in a vulnerable terminal, causing commands to execute in that privileged session and exposing sensitive files such as /etc/shadow. Suggested mitigations include disabling wall forwarding in journald.conf or via the kernel command line.

Get the actors, campaigns, and ATT&CK mapping behind it.
5 events from the most recent confirmed update back to the earliest known activity.
The systemd-journald flaw affecting emerg-level messages forwarded via wall was assigned CVE-2026-40228. The identifier formalized the issue previously disclosed by Aaron Rainbolt, which can allow local users to inject terminal control sequences into other users' TTYs under affected configurations.
In an oss-sec follow-up, Aaron Rainbolt said the upstream issue reference was correct but had been deleted by systemd maintainers. He said upstream viewed the disclosure policy as irresponsible, while his email preserved the useful details from the removed report.
A follow-up explanation detailed how the journald flaw can be chained with XTerm behavior associated with CVE-2022-45063 to achieve privilege escalation. In the demonstrated scenario, a crafted emerg-level message injected commands into a root ZSH session and copied /etc/shadow to a location readable by the attacker.
Rainbolt publicly disclosed that systemd-journald in systemd 259 fails to sanitize emerg-level messages broadcast to other users' terminals, enabling terminal output manipulation and possible exploitation of vulnerable terminal emulators. The disclosure included a basic proof of concept and mitigation advice such as disabling wall forwarding.
Aaron Rainbolt reportedly disclosed to upstream that systemd-journald in systemd 259 does not escape dangerous character sequences in emerg-level messages forwarded via wall. The flaw can let a local user inject terminal escape sequences into other users' TTYs when ForwardToWall=yes and MaxWallLevel=emerg are enabled.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
6 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open sourceseclists.org
Open sourceseclists.org
Open sourceseclists.org
Open sourceseclists.org
Open sourceseclists.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.