Security Flaw in Yggdrasil System Broker Allows Unauthorized Package Management
CVE-2025-3931
7.8HIGH
Key Information:
- Vendor
Red Hat
- Vendor
- CVE Published:
- 14 May 2025
What is CVE-2025-3931?
A security flaw in Yggdrasil, a system broker, allows unauthorized system users to communicate with worker processes via the DBus component. This vulnerability arises from the lack of necessary authentication and authorization checks on a DBus method used to dispatch messages to Yggdrasil worker processes. One of the workers functions as a package manager, which can install, remove, or modify system repositories. Consequently, an attacker with access to the system can exploit this flaw to install arbitrary RPM packages, potentially leading to local privilege escalation and unauthorized access to sensitive system data.
Affected Version(s)
Red Hat Enterprise Linux 10 0:0.4.5-3.el10_0