Amazon Linux 2023 Security Advisory: ALAS2023-2025-1006
Advisory Released Date: 2025-06-10
Advisory Updated Date: 2025-06-10
Severity:
Medium
Issue Overview:
TTY Hijacking while Attaching to a Multiuser Session in the screen package
Has potential to break some reattach use cases, but the specific use case was broken already before.
screen in Debian not installed setuid or setgid
DEBIANBUG: [1105191]
Info: https://www.openwall.com/lists/oss-security/2025/05/12/1
Patch: https://git.savannah.gnu.org/cgit/screen.git/commit/?id=049b26b22e197ba3be9c46e5c193032e01a4724a (CVE-2025-46802)
Affected Packages:
screen
Issue Correction:
Run dnf update screen --releasever 2023.7.20250609 to update your system.
New Packages:
aarch64:
screen-debuginfo-4.8.0-5.amzn2023.0.4.aarch64
screen-4.8.0-5.amzn2023.0.4.aarch64
screen-debugsource-4.8.0-5.amzn2023.0.4.aarch64
src:
screen-4.8.0-5.amzn2023.0.4.src
x86_64:
screen-debugsource-4.8.0-5.amzn2023.0.4.x86_64
screen-4.8.0-5.amzn2023.0.4.x86_64
screen-debuginfo-4.8.0-5.amzn2023.0.4.x86_64