CVE-2023-24626
published 2023-04-08CVE-2023-24626: socket.c in GNU Screen through 4.9.0, when installed setuid or setgid (the default on platforms such as Arch Linux and FreeBSD), allows local users to send a…
PriorityP427medium6.5CVSS 3.1
AVLACLPRLUINSCCNINAH
EXPLOIT
EPSS
0.54%
41.6th percentile
socket.c in GNU Screen through 4.9.0, when installed setuid or setgid (the default on platforms such as Arch Linux and FreeBSD), allows local users to send a privileged SIGHUP signal to any PID, causing a denial of service or disruption of the target process.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | screen | < screen 4.9.1-1 (forky) | screen 4.9.1-1 (forky) |
| gnu | screen | <= 4.9.0 | — |
| gnu | screen | >= 0 < 4.9.1-1 | 4.9.1-1 |
| gnu | screen | >= 0 < 4.9.1-1 | 4.9.1-1 |
| gnu | screen | >= 0 < 4.9.0-1ubuntu0.1 | 4.9.0-1ubuntu0.1 |
| gnu | screen | >= 0 < 4.9.1-1ubuntu1 | 4.9.1-1ubuntu1 |
| msrc | cbl2_screen_4.9.1-1_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
osv6.5MEDIUM
vendor_debian6.5LOW
vendor_msrc6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu6.5MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
screen vulnerabilities
osv·2026-01-26·CVSS 6.5
CVE-2023-24626 [MEDIUM] screen vulnerabilities
screen vulnerabilities
It was discovered that GNU Screen incorrectly handled signals when setuid
or setgid privileges were being used, which is not the default in Ubuntu.
A local attacker could use this issue to send privileged signals, possibly
leading to a denial of service. This issue only affected Ubuntu 22.04 LTS.
(CVE-2023-24626)
It was discovered that GNU Screen incorrectly handled PTY permissions. A
local attacker could possibly use this issue to connect to an unauthorized
screen session. (CVE-2025-46802)
It was discovered that GNU Screen incorrectly handled file access when
setuid privileges were being used, which is not the default in Ubuntu. A
local attacker could use this issue to deduce information about certain
file paths. (CVE-2025-46804)
It was discovered that GNU Scree
GHSA
GHSA-wr4w-95gx-6cfr: socket
ghsa_unreviewed·2023-04-08
CVE-2023-24626 [HIGH] CWE-732 GHSA-wr4w-95gx-6cfr: socket
socket.c in GNU Screen through 4.9.0, when installed setuid or setgid (the default on platforms such as Arch Linux and FreeBSD), allows local users to send a privileged SIGHUP signal to any PID, causing a denial of service or disruption of the target process.
OSV
CVE-2023-24626: socket
osv·2023-04-08·CVSS 6.5
CVE-2023-24626 [MEDIUM] CVE-2023-24626: socket
socket.c in GNU Screen through 4.9.0, when installed setuid or setgid (the default on platforms such as Arch Linux and FreeBSD), allows local users to send a privileged SIGHUP signal to any PID, causing a denial of service or disruption of the target process.
Ubuntu
GNU Screen vulnerabilities
vendor_ubuntu·2026-01-26·CVSS 6.5
CVE-2023-24626 [MEDIUM] GNU Screen vulnerabilities
Title: GNU Screen vulnerabilities
Summary: Several security issues were fixed in GNU Screen.
It was discovered that GNU Screen incorrectly handled signals when setuid
or setgid privileges were being used, which is not the default in Ubuntu.
A local attacker could use this issue to send privileged signals, possibly
leading to a denial of service. This issue only affected Ubuntu 22.04 LTS.
(CVE-2023-24626)
It was discovered that GNU Screen incorrectly handled PTY permissions. A
local attacker could possibly use this issue to connect to an unauthorized
screen session. (CVE-2025-46802)
It was discovered that GNU Screen incorrectly handled file access when
setuid privileges were being used, which is not the default in Ubuntu. A
local attacker could use this issue to deduce information about
Ubuntu
GNU Screen vulnerability
vendor_ubuntu·2023-07-03
CVE-2023-24626 GNU Screen vulnerability
Title: GNU Screen vulnerability
Summary: GNU Screen could be made to crash applications if it received specially
crafted input.
It was discovered that GNU Screen was not properly checking user
identifiers before sending certain signals to target processes. If GNU
Screen was installed as setuid or setgid, a local attacker could possibly
use this issue to cause a denial of service on a target application.
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
socket.c in GNU Screen through 4.9.0 when installed setuid or setgid (the default on platforms such as Arch Linux and FreeBSD) allows local users to send a privileged SIGHUP signal to any PID causing
vendor_msrc·2023-04-11·CVSS 6.5
CVE-2023-24626 [MEDIUM] CWE-732 socket.c in GNU Screen through 4.9.0 when installed setuid or setgid (the default on platforms such as Arch Linux and FreeBSD) allows local users to send a privileged SIGHUP signal to any PID causing
socket.c in GNU Screen through 4.9.0 when installed setuid or setgid (the default on platforms such as Arch Linux and FreeBSD) allows local users to send a privileged SIGHUP signal to any PID causing a denial of service or disruption of the target process.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact
Red Hat
screen: allows sending SIGHUP to arbitrary PIDs
vendor_redhat·2023-04-08·CVSS 6.5
CVE-2023-24626 [MEDIUM] CWE-862 screen: allows sending SIGHUP to arbitrary PIDs
screen: allows sending SIGHUP to arbitrary PIDs
socket.c in GNU Screen through 4.9.0, when installed setuid or setgid (the default on platforms such as Arch Linux and FreeBSD), allows local users to send a privileged SIGHUP signal to any PID, causing a denial of service or disruption of the target process.
A flaw was found in screen. This flaw allows local users to send a SIGHUP signal to any PID due to a missing signal sending permission check, potentially resulting in a denial of service or disruption of the target process.
Statement: The screen binary as shipped with Red Hat Enterprise Linux is installed with the set-group-ID mode bit set. However, the binary's group is set to screen and not root, limiting the security impact of this issue.
The screen package is not shipped in Red Ha
Debian
CVE-2023-24626: screen - socket.c in GNU Screen through 4.9.0, when installed setuid or setgid (the defau...
vendor_debian·2023·CVSS 6.5
CVE-2023-24626 [MEDIUM] CVE-2023-24626: screen - socket.c in GNU Screen through 4.9.0, when installed setuid or setgid (the defau...
socket.c in GNU Screen through 4.9.0, when installed setuid or setgid (the default on platforms such as Arch Linux and FreeBSD), allows local users to send a privileged SIGHUP signal to any PID, causing a denial of service or disruption of the target process.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 4.9.1-1)
sid: resolved (fixed in 4.9.1-1)
trixie: resolved (fixed in 4.9.1-1)
No detection rules found.
No writeups or analysis indexed.
https://git.savannah.gnu.org/cgit/screen.git/patch/?id=e9ad41bfedb4537a6f0de20f00b27c7739f168f7https://savannah.gnu.org/bugs/?63195https://www.exploit-db.com/exploits/51252https://git.savannah.gnu.org/cgit/screen.git/patch/?id=e9ad41bfedb4537a6f0de20f00b27c7739f168f7https://savannah.gnu.org/bugs/?63195https://security.netapp.com/advisory/ntap-20250509-0003/https://www.exploit-db.com/exploits/51252https://www.exploit-db.com/exploits/51252
2023-04-08
Published