CVE-2025-46802

Name
CVE-2025-46802
Description
For a short time they PTY is set to mode 666, allowing any user on the system to connect to the screen session.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
meissner@suse.de https://bugzilla.suse.com/show_bug.cgi?id=CVE-2025-46802
meissner@suse.de https://www.openwall.com/lists/oss-security/2025/05/12/1

Match rules

CPE URI Source package Min version Max version
suse-linux-enterprise-micro-5.3 >= ? < 4.6.2-150000.5.8.1
suse-linux-enterprise-micro-5.4 >= ? < 4.6.2-150000.5.8.1
suse-linux-enterprise-micro-5.5 >= ? < 4.6.2-150000.5.8.1
suse-linux-enterprise-module-for-basesystem-15-sp6 >= ? < 4.6.2-150000.5.8.1
suse-linux-enterprise-server-15-sp6 >= ? < 4.6.2-150000.5.8.1
suse-linux-enterprise-desktop-15-sp6 >= ? < 4.6.2-150000.5.8.1
suse-linux-enterprise-server-for-sap-applications-15-sp6 >= ? < 4.6.2-150000.5.8.1
suse-linux-enterprise-high-performance-computing-15-sp6 >= ? < 4.6.2-150000.5.8.1

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
screen edge-main 5.0.1-r0 Celeste <cielesti@protonmail.com> fixed
screen 3.23-main 5.0.1-r0 Celeste <cielesti@protonmail.com> fixed
screen 3.22-main 5.0.1-r0 Celeste <cielesti@protonmail.com> fixed
screen 3.21-main 5.0.1-r0 Celeste <cielesti@protonmail.com> fixed
screen 3.20-main 4.9.1_git20250512-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
screen 3.19-main 4.9.1_git20250512-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
screen 3.18-main 4.9.1_git20250512-r0 Natanael Copa <ncopa@alpinelinux.org> fixed