Bug 2364200 (CVE-2025-46803)

Summary: CVE-2025-46803 screen: Screen by Default Creates World Writable PTYs
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: security-response-team
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in Screen. The default mode for pseudo-terminals (PTYs) allocated by Screen was changed from 0620 to 0622. This vulnerability allows public writes to any PTYs in the system.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2368500, 2368501    
Bug Blocks:    

Description OSIDB Bzimport 2025-05-05 20:11:45 UTC
In Screen version 5.0.0 the default mode of pseudo terminals (PTYs) allocated
by Screen was changed from 0620 to 0622, thereby allowing public writes
to any of its PTYs in the system.