ALAS2023-2025-1006


Amazon Linux 2023 Security Advisory: ALAS2023-2025-1006
Advisory Released Date: 2025-06-10
Advisory Updated Date: 2025-06-10
Severity: Medium

Issue Overview:

TTY Hijacking while Attaching to a Multiuser Session in the screen package

Has potential to break some reattach use cases, but the specific use case was broken already before.
screen in Debian not installed setuid or setgid
DEBIANBUG: [1105191]

Info: https://www.openwall.com/lists/oss-security/2025/05/12/1
Patch: https://git.savannah.gnu.org/cgit/screen.git/commit/?id=049b26b22e197ba3be9c46e5c193032e01a4724a (CVE-2025-46802)


Affected Packages:

screen


Issue Correction:
Run dnf update screen --releasever 2023.7.20250609 to update your system.

New Packages:
aarch64:
    screen-debuginfo-4.8.0-5.amzn2023.0.4.aarch64
    screen-4.8.0-5.amzn2023.0.4.aarch64
    screen-debugsource-4.8.0-5.amzn2023.0.4.aarch64

src:
    screen-4.8.0-5.amzn2023.0.4.src

x86_64:
    screen-debugsource-4.8.0-5.amzn2023.0.4.x86_64
    screen-4.8.0-5.amzn2023.0.4.x86_64
    screen-debuginfo-4.8.0-5.amzn2023.0.4.x86_64