Multiple Security Issues Found in Screen Terminal Multiplexer
2025-05-13
A security audit uncovered multiple vulnerabilities in the widely used screen terminal multiplexer. The most critical is a local root privilege escalation vulnerability (CVE-2025-23395) affecting Screen 5.0.0 running with setuid-root privileges. This allows unprivileged users to create files with root ownership in arbitrary locations. Additional vulnerabilities include TTY hijacking (CVE-2025-46802), world-writable PTYs (CVE-2025-46803), and other information leaks and race conditions. Patches have been released, and users are urged to update to the patched versions and avoid running Screen with setuid-root privileges.
Development
screen