Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 521
Alerts This Week
Warning Icon 1 521

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 25 articles for you...
100

SUSE Linux Micro 6.1 Screen Moderate Update CVE-2025-46802

An update that solves one vulnerability can now be installed.. # Security update for screen Announcement ID: SUSE-SU-2026:20406-1 Release Date: 2025-06-05T15:44:22Z Rating: moderate References: * bsc#1242269 Cross-References: * CVE-2025-46802 CVSS scores: * CVE-2025-46802 ( SUSE ): 5.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-46802 ( SUSE ): 6.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N * CVE-2025-46802 ( NVD ): 5.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-46802 ( NVD ): 6.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N Affected Products: * SUSE Linux Micro 6.1 * SUSE Linux Micro Extras 6.1 An update that solves one vulnerability can now be installed. ## Description: This update for screen fixes the following issues: This update also ships screen to SL Micro 6.1 Extras. * also use tty fd passing after a suspend (MSG_CONT) * do not chmod the tty for multiattach, rely on tty fd passing instead [bsc#1242269] [CVE-2025-46802] * fix resume after suspend in multiuser mode ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro Extras 6.1 zypper in -t patch SUSE-SLE-Micro-Extras-6.1-135=1 ## Package List: * SUSE Linux Micro Extras 6.1 (aarch64 ppc64le s390x x86_64) * screen-debugsource-4.9.1-slfo.1.1_2.1 * libutempter0-debuginfo-1.2.1-slfo.1.1_1.3 * screen-4.9.1-slfo.1.1_2.1 * screen-debuginfo-4.9.1-slfo.1.1_2.1 * libutempter0-1.2.1-slfo.1.1_1.3 * utempter-debugsource-1.2.1-slfo.1.1_1.3 ## References: * https://www.suse.com/security/cve/CVE-2025-46802.html * https://bugzilla.suse.com/show_bug.cgi?id=1242269 . SUSE's update for screen addresses a moderatebuffer overflow issue, enhancing system security. Install promptly to mitigate risk.. SUSE Linux screen update moderate patch buffer overflow. . LinuxSecurity.com Team

Calendar%202 Feb 17, 2026 SuSE
100

SUSE Linux Mini 7.2 Safety Notice SUSE-QUO-2027-31377-1 CVE-2026-57912

An update that solves one vulnerability can now be installed.. # Security update for screen Announcement ID: SUSE-SU-2026:20304-1 Release Date: 2025-06-23T13:47:42Z Rating: moderate References: * bsc#1242269 Cross-References: * CVE-2025-46802 CVSS scores: * CVE-2025-46802 ( SUSE ): 5.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-46802 ( SUSE ): 6.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N * CVE-2025-46802 ( NVD ): 5.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-46802 ( NVD ): 6.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N Affected Products: * SUSE Linux Micro 6.0 * SUSE Linux Micro Extras 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for screen fixes the following issues: * CVE-2025-46802: Fixed temporary chown() of users' TTY to mode 0666 allowing PTY hijacking (bsc#1242269) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro Extras 6.0 zypper in -t patch SUSE-SLE-Micro-Extras-6.0-364=1 ## Package List: * SUSE Linux Micro Extras 6.0 (aarch64 ppc64le s390x x86_64) * screen-debugsource-4.9.1-2.1 * screen-4.9.1-2.1 * screen-debuginfo-4.9.1-2.1 ## References: * https://www.suse.com/security/cve/CVE-2025-46802.html * https://bugzilla.suse.com/show_bug.cgi?id=1242269 . Update to fix the CVE-2025-46802 vulnerability in SUSE's screen application reduces risks related to PTY hijacking.. SUSE screen update PTY hijacking security. . LinuxSecurity.com Team

Calendar%202 Feb 13, 2026 SuSE
172

Ubuntu 22.04 7978-1 GNU Screen Important Local Attack Risks

Several security issues were fixed in GNU Screen.. ========================================================================== Ubuntu Security Notice USN-7978-1 January 26, 2026 screen vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Several security issues were fixed in GNU Screen. Software Description: - screen: terminal multiplexer with VT100/ANSI terminal emulation Details: It was discovered that GNU Screen incorrectly handled signals when setuid or setgid privileges were being used, which is not the default in Ubuntu. A local attacker could use this issue to send privileged signals, possibly leading to a denial of service. This issue only affected Ubuntu 22.04 LTS. (CVE-2023-24626) It was discovered that GNU Screen incorrectly handled PTY permissions. A local attacker could possibly use this issue to connect to an unauthorized screen session. (CVE-2025-46802) It was discovered that GNU Screen incorrectly handled file access when setuid privileges were being used, which is not the default in Ubuntu. A local attacker could use this issue to deduce information about certain file paths. (CVE-2025-46804) It was discovered that GNU Screen incorrectly handled signals when setuid privileges were being used, which is not the default in Ubuntu. A local attacker could use this issue to send privileged signals, possibly leading to a denial of service. (CVE-2025-46805) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS screen 4.9.1-1ubuntu1 Ubuntu 22.04 LTS screen 4.9.0-1ubuntu0.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7978-1 CVE-2023-24626, CVE-2025-46802, CVE-2025-46804, CVE-2025-46805 Package Information: https://launchpad.net/ubuntu/+source/screen/4.9.1-1ubuntu1 https://launchpad.net/ubuntu/+source/screen/4.9.0-1ubuntu0.1 . Multiple security issues fixed in GNU Screen for Ubuntu 22.04 and 24.04 LTS, addressing denial of service risks and unauthorized access.. GNU Screen vulnerabilities, Ubuntu security updates, terminal multiplexer issues. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jan 26, 2026 Important Ubuntu
89

Fedora 41: screen Critical Update for Configuration Issues 2025-653690f2f7

Update default config options for build. New upstream release 5.0.1 . -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-653690f2f7 2025-07-19 21:46:55.252343+00:00 -------------------------------------------------------------------------------- Name : screen Product : Fedora 41 Version : 5.0.1 Release : 4.fc41 URL : http://www.gnu.org/software/screen Summary : A screen manager that supports multiple logins on one terminal Description : The screen utility allows you to have multiple logins on just one terminal. Screen is useful for users who telnet into a machine or are connected via a dumb terminal, but want to use more than just one login. Install the screen package if you need a screen manager that can support multiple logins on one terminal. -------------------------------------------------------------------------------- Update Information: Update default config options for build. New upstream release 5.0.1 -------------------------------------------------------------------------------- ChangeLog: * Mon Jun 30 2025 Josef Ridky - 5.0.1-4 - Modify configuration options to reflect changes in version 5.0.1 * Sat Jun 28 2025 Charles R. Anderson - 5.0.1-3 - Add --enable-socket-dir - Resolves: rhbz#2375347 * Wed Jun 25 2025 Josef Ridky - 5.0.1-2 - Unify patch name * Thu May 29 2025 Dick Marinus - 5.0.1-1 - New upstream release 5.0.1 (#2366507) * Tue Feb 11 2025 Zbigniew J\u0119drzejewski-Szmek - 5.0.0-4 - Add sysusers.d config file to allow rpm to create users/groups automatically * Sat Feb 1 2025 Bjrn Esser - 5.0.0-3 - Add explicit BR: libxcrypt-devel * Sun Jan 19 2025 Fedora Release Engineering - 5.0.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild * Thu Aug 29 2024 Josef Ridky - 5.0.0-1 - New upsream release 5.0.0(#2308450) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2362065 - [abrt] screen: strncpy(): screen killed by SIGABRT https://bugzilla.redhat.com/show_bug.cgi?id=2362065 [ 2 ] Bug #2366507 - screen-5.0.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2366507 [ 3 ] Bug #2367169 - Backport to F42: Add sysusers.d config file to allow rpm to create users/groups automatically https://bugzilla.redhat.com/show_bug.cgi?id=2367169 [ 4 ] Bug #2368500 - CVE-2025-46803 screen: Screen by Default Creates World Writable PTYs [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2368500 [ 5 ] Bug #2368501 - CVE-2025-46803 screen: Screen by Default Creates World Writable PTYs [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2368501 [ 6 ] Bug #2368503 - CVE-2025-46802 screen: TTY Hijacking while Attaching to a Multiuser Session [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2368503 [ 7 ] Bug #2368504 - CVE-2025-46802 screen: TTY Hijacking while Attaching to a Multiuser Session [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2368504 [ 8 ] Bug #2374606 - CVE-2025-23395 screen: Local Root Exploit via `logfile_reopen()` [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2374606 [ 9 ] Bug #2375347 - screen changed location of sockets--now in $HOME/.screen rather than /run/screen https://bugzilla.redhat.com/show_bug.cgi?id=2375347 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-653690f2f7' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Important enhancements to display management in Fedora 41 tackle various challenges, bolstering both security and efficiency.. Fedora, screen, security advisory, update, configuration. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 19, 2025 Critical Fedora
89

Fedora 42: Local Root Exploit and Configuration Update Announcement

Update default config options for build. New upstream release 5.0.1 . -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-f055a0d751 2025-07-19 21:31:40.396395+00:00 -------------------------------------------------------------------------------- Name : screen Product : Fedora 42 Version : 5.0.1 Release : 4.fc42 URL : http://www.gnu.org/software/screen Summary : A screen manager that supports multiple logins on one terminal Description : The screen utility allows you to have multiple logins on just one terminal. Screen is useful for users who telnet into a machine or are connected via a dumb terminal, but want to use more than just one login. Install the screen package if you need a screen manager that can support multiple logins on one terminal. -------------------------------------------------------------------------------- Update Information: Update default config options for build. New upstream release 5.0.1 -------------------------------------------------------------------------------- ChangeLog: * Mon Jun 30 2025 Josef Ridky - 5.0.1-4 - Modify configuration options to reflect changes in version 5.0.1 * Sat Jun 28 2025 Charles R. Anderson - 5.0.1-3 - Add --enable-socket-dir - Resolves: rhbz#2375347 * Wed Jun 25 2025 Josef Ridky - 5.0.1-2 - Unify patch name * Thu May 29 2025 Dick Marinus - 5.0.1-1 - New upstream release 5.0.1 (#2366507) * Tue Feb 11 2025 Zbigniew J\u0119drzejewski-Szmek - 5.0.0-4 - Add sysusers.d config file to allow rpm to create users/groups automatically * Sat Feb 1 2025 Bjrn Esser - 5.0.0-3 - Add explicit BR: libxcrypt-devel -------------------------------------------------------------------------------- References: [ 1 ] Bug #2362065 - [abrt] screen: strncpy(): screen killed by SIGABRT https://bugzilla.redhat.com/show_bug.cgi?id=2362065 [ 2 ] Bug #2366507 - screen-5.0.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2366507 [ 3 ] Bug #2367169 - Backport to F42: Add sysusers.d config file to allow rpm to create users/groups automatically https://bugzilla.redhat.com/show_bug.cgi?id=2367169 [ 4 ] Bug #2368500 - CVE-2025-46803 screen: Screen by Default Creates World Writable PTYs [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2368500 [ 5 ] Bug #2368501 - CVE-2025-46803 screen: Screen by Default Creates World Writable PTYs [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2368501 [ 6 ] Bug #2368503 - CVE-2025-46802 screen: TTY Hijacking while Attaching to a Multiuser Session [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2368503 [ 7 ] Bug #2368504 - CVE-2025-46802 screen: TTY Hijacking while Attaching to a Multiuser Session [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2368504 [ 8 ] Bug #2374606 - CVE-2025-23395 screen: Local Root Exploit via `logfile_reopen()` [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2374606 [ 9 ] Bug #2375347 - screen changed location of sockets--now in $HOME/.screen rather than /run/screen https://bugzilla.redhat.com/show_bug.cgi?id=2375347 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-f055a0d751' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Fedora 42 release tackles security vulnerabilities and settings adjustments in the screen tool. Prompt upgrade advised.. Fedora 42, screen utility, system security fixes, softwareupdate. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 19, 2025 Important Fedora
100

SUSE: 2025:02186-1 moderate: CVE-2025-46802 TTY hijacking

* bsc#1242269 Cross-References: * CVE-2025-46802 . # Security update for screen Announcement ID: SUSE-SU-2025:02186-1 Release Date: 2025-07-01T11:48:02Z Rating: moderate References: * bsc#1242269 Cross-References: * CVE-2025-46802 CVSS scores: * CVE-2025-46802 ( SUSE ): 5.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-46802 ( SUSE ): 6.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N * CVE-2025-46802 ( NVD ): 5.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-46802 ( NVD ): 6.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for screen fixes the following issues: Security issues fixed: * CVE-2025-46802: temporary `chmod` of a user's TTY to mode 0666 when attempting to attach to a multi-user session allows for TTY hijacking (bsc#1242269). Other issues fixed: * Use TTY file descriptor passing after a suspend (`MSG_CONT`). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2025-2186=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * screen-4.0.4-23.9.1 * screen-debuginfo-4.0.4-23.9.1 * screen-debugsource-4.0.4-23.9.1 ## References: * https://www.suse.com/security/cve/CVE-2025-46802.html * https://bugzilla.suse.com/show_bug.cgi?id=1242269 . The Debian securitynotice highlights CVE-2025-46803, a significant vulnerability that permits unauthorized access to secret keys.. SUSE Linux Enterprise,Tty Hijacking,Security Update,Screen Application. . LinuxSecurity.com Team

Calendar%202 Jul 01, 2025 SuSE
100

SUSE: 2025:20439-1 moderate: screen PTY security breach issue

* bsc#1242269 Cross-References: * CVE-2025-46802 . # Security update for screen Announcement ID: SUSE-SU-2025:20439-1 Release Date: 2025-06-23T13:47:42Z Rating: moderate References: * bsc#1242269 Cross-References: * CVE-2025-46802 CVSS scores: * CVE-2025-46802 ( SUSE ): 5.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-46802 ( SUSE ): 6.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N * CVE-2025-46802 ( NVD ): 5.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-46802 ( NVD ): 6.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N Affected Products: * SUSE Linux Micro Extras 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for screen fixes the following issues: * CVE-2025-46802: Fixed temporary chown() of users' TTY to mode 0666 allowing PTY hijacking (bsc#1242269) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro Extras 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-364=1 ## Package List: * SUSE Linux Micro Extras 6.0 (aarch64 s390x x86_64) * screen-debugsource-4.9.1-2.1 * screen-4.9.1-2.1 * screen-debuginfo-4.9.1-2.1 ## References: * https://www.suse.com/security/cve/CVE-2025-46802.html * https://bugzilla.suse.com/show_bug.cgi?id=1242269 . Revision for display identifiers addresses significant concern linked to CVE-2025-46802, prioritizing system reliability and user protection.. SUSE Linux Micro, security update, PTY hijacking, CVE-2025-46802. . LinuxSecurity.com Team

Calendar%202 Jun 26, 2025 SuSE
202

openSUSE Leap 15.6: 2025:02016-1 moderate: screen TTY hijacking

An update that solves one vulnerability can now be installed.. # Security update for screen Announcement ID: SUSE-SU-2025:02016-1 Release Date: 2025-06-19T07:14:49Z Rating: moderate References: * bsc#1242269 Cross-References: * CVE-2025-46802 CVSS scores: * CVE-2025-46802 ( SUSE ): 5.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-46802 ( SUSE ): 6.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N * CVE-2025-46802 ( NVD ): 5.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-46802 ( NVD ): 6.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N Affected Products: * Basesystem Module 15-SP6 * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for screen fixes the following issues: Security issues fixed: * CVE-2025-46802: temporary `chmod` of a user's TTY to mode 0666 when attempting to attach to a multi-user session allows for TTY hijacking (bsc#1242269). Other issues fixed: * Use TTY file descriptor passing after a suspend (`MSG_CONT`). * Fix resume after suspend in multi-user mode. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-2016=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2025-2016=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2025-2016=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2025-2016=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2025-2016=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2025-2016=1 * Basesystem Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2025-2016=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2025-2016=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * screen-4.6.2-150000.5.8.1 * screen-debuginfo-4.6.2-150000.5.8.1 * screen-debugsource-4.6.2-150000.5.8.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * screen-4.6.2-150000.5.8.1 * screen-debuginfo-4.6.2-150000.5.8.1 * screen-debugsource-4.6.2-150000.5.8.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * screen-4.6.2-150000.5.8.1 * screen-debuginfo-4.6.2-150000.5.8.1 * screen-debugsource-4.6.2-150000.5.8.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * screen-4.6.2-150000.5.8.1 * screen-debuginfo-4.6.2-150000.5.8.1 * screen-debugsource-4.6.2-150000.5.8.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * screen-4.6.2-150000.5.8.1 * screen-debuginfo-4.6.2-150000.5.8.1 * screen-debugsource-4.6.2-150000.5.8.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * screen-4.6.2-150000.5.8.1 * screen-debuginfo-4.6.2-150000.5.8.1 * screen-debugsource-4.6.2-150000.5.8.1 * Basesystem Module 15-SP6 (aarch64 ppc64le s390x x86_64) * screen-4.6.2-150000.5.8.1 *screen-debuginfo-4.6.2-150000.5.8.1 * screen-debugsource-4.6.2-150000.5.8.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * screen-4.6.2-150000.5.8.1 * screen-debuginfo-4.6.2-150000.5.8.1 * screen-debugsource-4.6.2-150000.5.8.1 ## References: * https://www.suse.com/security/cve/CVE-2025-46802.html * https://bugzilla.suse.com/show_bug.cgi?id=1242269 . Important security update for display in openSUSE addresses TTY takeover risk. Upgrade promptly to safeguard your system against vulnerabilities.. openSUSE security, screen update, system patch, TTY issue. . LinuxSecurity.com Team

Calendar%202 Jun 19, 2025 OpenSUSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200