CVE-2025-46803

NameCVE-2025-46803
DescriptionThe default mode of pseudo terminals (PTYs) allocated by Screen was changed from 0620 to 0622, thereby allowing anyone to write to any Screen PTYs in the system.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
screen (PTS)bullseye4.8.0-6fixed
bookworm4.9.0-4fixed
sid, trixie4.9.1-3fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
screensource(unstable)(not affected)

Notes

- screen <not-affected> (Vulnerable code only introduced in Scren v5 branch)
Introduced with: https://git.savannah.gnu.org/cgit/screen.git/commit/?id=78a961188f7da528c7cefcc63e07f35f04e69a93 (v.5.0.0)
Fixed by: https://git.savannah.gnu.org/cgit/screen.git/commit/?id=d5d7bf43f3842e8b62d5f34eb4b031de7c8098c1
https://www.openwall.com/lists/oss-security/2025/05/12/1

Search for package or bug name: Reporting problems