CVE-2025-3931 Details
Description
A flaw was found in Yggdrasil, which acts as a system broker, allowing the processes to communicate to other children's "worker" processes through the DBus component. Yggdrasil creates a DBus method to dispatch messages to workers. However, it misses authentication and authorization checks, allowing every system user to call it. One available Yggdrasil worker acts as a package manager with capabilities to create and enable new repositories and install or remove packages. This flaw allows an attacker with access to the system to leverage the lack of authentication on the dispatch message to force the Yggdrasil worker to install arbitrary RPM packages. This issue results in local privilege escalation, enabling the attacker to access and modify sensitive system data.
A local privilege escalation vulnerability exists in Yggdrasil, a system broker that facilitates communication between processes and their worker processes via DBus. The issue arises because Yggdrasil's DBus method for dispatching messages to workers lacks authentication and authorization checks, allowing any system user to invoke it. This flaw is particularly concerning as one of the Yggdrasil workers functions as a package manager, capable of managing software repositories and RPM packages. Exploiting this vulnerability could enable an attacker with system access to manipulate the package manager into installing arbitrary RPMs, thereby gaining elevated privileges and access to sensitive system information.
Users can upgrade to the patched version of Yggdrasil available in Red Hat Enterprise Linux 10. For instructions on applying this update, refer to the Red Hat Enterprise Linux 10 Yggdrasil Security Update article.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 14, 2025CISA-ADP
Assessed May 14, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2025:7592 | [email protected] | AdvisoryRemedyVendor |
| https://access.redhat.com/security/cve/CVE-2025-3931 | [email protected] | AdvisoryRemedyVendor |
| https://bugzilla.redhat.com/show_bug.cgi?id=2362345 | [email protected] | Issue TrackingTechnical DescriptionVendor |
| https://github.com/RedHatInsights/yggdrasil/pull/336 | [email protected] | Issue TrackingVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-280 | Improper Handling of Insufficient Permissions or Privileges | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Red Hat Yggdrasil | All versions |
CPE
Remediation
| |
| Red Hat Enterprise Linux | < 10.1 |
CPE
Remediation
| |
| Red Hat CodeReady Linux Builder | < 10.1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 25, 2025 | CVE Modified | [email protected] |
| May 14, 2025 | New CVE Received | [email protected] |
Volerion