CVE-2025-46805

Name
CVE-2025-46805
Description
Screen version 5.0.0 and older version 4 releases have a TOCTOU race potentially allowing to send SIGHUP, SIGCONT to privileged processes when installed setuid-root.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
meissner@suse.de https://bugzilla.suse.com/show_bug.cgi?id=CVE-2025-46805
meissner@suse.de https://www.openwall.com/lists/oss-security/2025/05/12/1

Match rules

CPE URI Source package Min version Max version
shopxo >= 5.0. <= 5.0.0
shopxo >= ? <= 4.9.1

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
screen edge-main 5.0.1-r0 Celeste <cielesti@protonmail.com> fixed
screen 3.23-main 5.0.1-r0 Celeste <cielesti@protonmail.com> fixed
screen 3.22-main 5.0.1-r0 Celeste <cielesti@protonmail.com> fixed
screen 3.21-main 5.0.1-r0 Celeste <cielesti@protonmail.com> fixed
screen 3.20-main 4.9.1_git20250512-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
screen 3.19-main 4.9.1_git20250512-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
screen 3.18-main 4.9.1_git20250512-r0 Natanael Copa <ncopa@alpinelinux.org> fixed