A crash was reported in gnu screen when processing a specially crafted sequence of combining characters. The cause is an out of bounds write, which may be exploitable to cause arbitrary code execution. https://lists.gnu.org/archive/html/screen-devel/2021-02/msg00000.html https://www.openwall.com/lists/oss-security/2021/02/09/3 Upstream bug: https://savannah.gnu.org/bugs/?60030
Created gnome-screensaver tracking bugs for this issue: Affects: fedora-all [bug 1927066]
*** Bug 1926949 has been marked as a duplicate of this bug. ***
Mitigation: This flaw is in utf8 processing; if your screen configuration does not enable utf8 (through configuration such as "defencoding utf-8" in .screenrc), you are not vulnerable.
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2021:0742 https://access.redhat.com/errata/RHSA-2021:0742
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2021-26937
This issue has been addressed in the following products: Red Hat Enterprise Linux 7.7 Advanced Update Support Red Hat Enterprise Linux 7.7 Update Services for SAP Solutions Red Hat Enterprise Linux 7.7 Telco Extended Update Support Via RHSA-2022:1074 https://access.redhat.com/errata/RHSA-2022:1074