https://seclists.org/oss-sec/2025/q2/154: scen: Multiple Security Issues in Scen (mostly affecting lease 5.0.0 and setuid-root installations)
Published May 16, 2025
·Updated
Affected Software
3 affected components
GNU Screen
Arch Linux screen
NetBSD screen (pkgsrc)
Frequently Asked Questions
1
What is the severity of CVE-2025-XXXX?
CVE-2025-XXXX is rated as high severity due to its potential to allow local root privilege escalation in affected installations.
2
How do I fix CVE-2025-XXXX?
To fix CVE-2025-XXXX, update to the latest version of GNU Screen that addresses the vulnerabilities.
3
Which versions are affected by CVE-2025-XXXX?
CVE-2025-XXXX mainly affects GNU Screen 5.0.0 and setuid-root installations.
4
What distributions are impacted by CVE-2025-XXXX?
CVE-2025-XXXX affects distributions that ship GNU Screen as a setuid-root application, notably Arch Linux and NetBSD.
5
Is there a known exploit for CVE-2025-XXXX?
Yes, there is a local root exploit associated with CVE-2025-XXXX in the Screen 5.0.0 update that affects specific distributions.