CVE-2025-46802 describes a privilege escalation vulnerability where a PTY is temporarily set to mode 666, allowing any local user to connect to a screen session. This medium-severity flaw (CVSS 6.0) requires low privileges and user interaction, but has high impact on confidentiality and integrity. There is currently no public exploit code available, no evidence of active exploitation, and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| SUSE | SUSE Linux Enterprise Desktop 15 SP6 | >= ?, < 4.6.2-150000.5.8.1CNA affecteddefault unaffected | |
| SUSE | SUSE Linux Enterprise High Performance Computing 15 SP6 | >= ?, < 4.6.2-150000.5.8.1CNA affecteddefault unaffected | |
| SUSE | SUSE Linux Enterprise Micro 5.3 | >= ?, < 4.6.2-150000.5.8.1CNA affecteddefault unaffected | |
| SUSE | SUSE Linux Enterprise Micro 5.4 | >= ?, < 4.6.2-150000.5.8.1CNA affecteddefault unaffected | |
| SUSE | SUSE Linux Enterprise Micro 5.5 | >= ?, < 4.6.2-150000.5.8.1CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.