Back

MEDIUM

Temporary chown() of users' TTY to mode 0666 allows PTY hijacking in screen

Published May 26, 2025

Description

For a short time they PTY is set to mode 666, allowing any user on the system to connect to the screen session.

Affected products

Remediation

Red Hat statement

This vulnerability is an Important local privilege escalation vector rather than a mere moderate flaw due to its exploitation potential during the short-lived but dangerously permissive window created by chmod(attach_tty, 0666). Even though the exposure of the TTY permissions may appear transient, this window allows attackers with local access to reliably read and inject arbitrary data into the victim’s TTY, including sensitive inputs like passwords or session-specific commands. The race condition inherent in the Attach() function’s logic multiplies the risk since TTY access for the duration of this window can be repeatedly attempted and exploited with high success rates. Furthermore, this vulnerability bypasses the usual privilege separation model of multi-user systems by enabling an unprivileged attacker to subvert the victim’s TTY in ways that can directly compromise the user’s session integrity and lead to further exploitation, such as terminal escape attacks or sophisticated phishing scenarios.

Red Hat mitigation

No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability.

References (7)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner suse
Published May 26, 2025
Updated May 27, 2025
Reserved Apr 30, 2025

CISA Vulnrichment

Updated May 27, 2025

NVD

Status Deferred
Modified Jun 17, 2026

Red Hat

Severity Important
Public date May 13, 2025
Bugzilla 2364199

ENISA EUVD

Assigner suse
Published May 26, 2025
Updated May 27, 2025

GitHub

No data