Security Flaw in Yggdrasil System Broker Allows Unauthorized Package Management
CVE-2025-3931

7.8HIGH

What is CVE-2025-3931?

A security flaw in Yggdrasil, a system broker, allows unauthorized system users to communicate with worker processes via the DBus component. This vulnerability arises from the lack of necessary authentication and authorization checks on a DBus method used to dispatch messages to Yggdrasil worker processes. One of the workers functions as a package manager, which can install, remove, or modify system repositories. Consequently, an attacker with access to the system can exploit this flaw to install arbitrary RPM packages, potentially leading to local privilege escalation and unauthorized access to sensitive system data.

Affected Version(s)

Red Hat Enterprise Linux 10 0:0.4.5-3.el10_0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.