CVE-2025-46802

NameCVE-2025-46802
DescriptionFor a short time they PTY is set to mode 666, allowing any user on the system to connect to the screen session.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1105191

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
screen (PTS)bullseye4.8.0-6vulnerable
bookworm4.9.0-4vulnerable
trixie, sid4.9.1-3fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
screensource(unstable)4.9.1-3unimportant1105191

Notes

Fixed by: https://git.savannah.gnu.org/cgit/screen.git/commit/?id=049b26b22e197ba3be9c46e5c193032e01a4724a
https://www.openwall.com/lists/oss-security/2025/05/12/1
Has potential to break some reattach use cases, but the specific use case
was broken already before.
screen in Debian not installed setuid or setgid

Search for package or bug name: Reporting problems