Temporary chown() of users' TTY to mode 0666 allows PTY hijacking in screen
Published May 26, 2025
5.3
MEDIUMCVSS 4.0
EPSS 0.23%
Description
For a short time they PTY is set to mode 666, allowing any user on the system to connect to the screen session.
Affected products
-
Affected
- ≥ ?, < 4.6.2-150000.5.8.1
-
Affected
- ≥ ?, < 4.6.2-150000.5.8.1
-
Affected
- ≥ ?, < 4.6.2-150000.5.8.1
-
Affected
- ≥ ?, < 4.6.2-150000.5.8.1
-
Affected
- ≥ ?, < 4.6.2-150000.5.8.1
-
Affected
- ≥ ?, < 4.6.2-150000.5.8.1
-
Affected
- ≥ ?, < 4.6.2-150000.5.8.1
-
Affected
- ≥ ?, < 4.6.2-150000.5.8.1
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| SUSE | SUSE Linux Enterprise Desktop 15 SP6 | unaffected | Affected
|
| SUSE | SUSE Linux Enterprise High Performance Computing 15 SP6 | unaffected | Affected
|
| SUSE | SUSE Linux Enterprise Micro 5.3 | unaffected | Affected
|
| SUSE | SUSE Linux Enterprise Micro 5.4 | unaffected | Affected
|
| SUSE | SUSE Linux Enterprise Micro 5.5 | unaffected | Affected
|
| SUSE | SUSE Linux Enterprise Module for Basesystem 15 SP6 | unaffected | Affected
|
| SUSE | SUSE Linux Enterprise Server 15 SP6 | unaffected | Affected
|
| SUSE | SUSE Linux Enterprise Server for SAP Applications 15 SP6 | unaffected | Affected
|
No data.
No data.
Red Hat Enterprise Linux 6
screen
Out of support scope
Red Hat Enterprise Linux 7
screen
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | screen | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | screen | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This vulnerability is an Important local privilege escalation vector rather than a mere moderate flaw due to its exploitation potential during the short-lived but dangerously permissive window created by chmod(attach_tty, 0666). Even though the exposure of the TTY permissions may appear transient, this window allows attackers with local access to reliably read and inject arbitrary data into the victim’s TTY, including sensitive inputs like passwords or session-specific commands. The race condition inherent in the Attach() function’s logic multiplies the risk since TTY access for the duration of this window can be repeatedly attempted and exploited with high success rates. Furthermore, this vulnerability bypasses the usual privilege separation model of multi-user systems by enabling an unprivileged attacker to subvert the victim’s TTY in ways that can directly compromise the user’s session integrity and lead to further exploitation, such as terminal escape attacks or sophisticated phishing scenarios.
Red Hat mitigation
No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability.
References (7)
- https://access.redhat.com/security/cve/CVE-2025-46802 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2364199 Issue Tracking
- https://bugzilla.suse.com/show_bug.cgi?id=CVE-2025-46802
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-28068 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-46802
- https://www.cve.org/CVERecord?id=CVE-2025-46802
- https://www.openwall.com/lists/oss-security/2025/05/12/1 exploit
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data