CVE-2025-46804 Details
Description
A minor information leak when running Screen with setuid-root privileges allows unprivileged users to deduce information about a path that would otherwise not be available. Affected are older Screen versions, as well as version 5.0.0.
A minor information leak vulnerability has been identified in GNU Screen versions through 5.0.0, when the application is run with setuid-root privileges. This vulnerability allows unprivileged users to infer information about file paths that would typically remain inaccessible. The issue arises from the way Screen handles socket path inspections with elevated privileges, inadvertently disclosing path information through error messages. Exploitation can be achieved by manipulating the SCREENDIR environment variable to test the existence of specific files or directories.
Users are advised to avoid running GNU Screen with setuid-root privileges. If multi-user features are needed, consider using a version of Screen that does not require elevated privileges or restricting the feature to trusted users.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 26, 2025CISA-ADP
Assessed May 27, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://bugzilla.suse.com/show_bug.cgi?id=CVE-2025-46804 | [email protected] | Issue TrackingTechnical DescriptionVendor |
| https://www.openwall.com/lists/oss-security/2025/05/12/1 | [email protected] | BundleMailing ListRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-203 | Observable Discrepancy | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| GNU Screen | <= 5.0.0 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 27, 2025 | CVE Modified | [email protected] |
| May 26, 2025 | New CVE Received | [email protected] |
Volerion