Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2025-3931 Details

ANALYZED


This CVE record has been analyzed and enriched by NVDAPI.com as an independent party.

Description

A flaw was found in Yggdrasil, which acts as a system broker, allowing the processes to communicate to other children's "worker" processes through the DBus component. Yggdrasil creates a DBus method to dispatch messages to workers. However, it misses authentication and authorization checks, allowing every system user to call it. One available Yggdrasil worker acts as a package manager with capabilities to create and enable new repositories and install or remove packages. This flaw allows an attacker with access to the system to leverage the lack of authentication on the dispatch message to force the Yggdrasil worker to install arbitrary RPM packages. This issue results in local privilege escalation, enabling the attacker to access and modify sensitive system data.

Metrics

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-280Improper Handling of Insufficient Permissions or Privileges[email protected]

Affected Products

ProductVersions
Red Hat Yggdrasil
All versions

CPE

  • No CPEs found in CPE dictionary for this product.

Remediation

  • No remediation found in references.
Red Hat Enterprise Linux
< 10.1

CPE

  • cpe:2.3:o:redhat:enterprise_linux:*:*:*:*:*:*:*:*
  • cpe:2.3:o:redhat:enterprise_linux_server:*:*:*:*:*:*:*:*

Remediation

Red Hat CodeReady Linux Builder
< 10.1

CPE

  • cpe:2.3:a:redhat:codeready_linux_builder:*:*:*:*:*:*:*:*

Remediation

Change History

4 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2025-3931
NVD Published Date:
May 14, 2025
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2025-3931 Details - Not Deferred