Input validation error in YAML-LibYAML - CVE-2025-40908

 

Input validation error in YAML-LibYAML - CVE-2025-40908

Published: June 10, 2025


Vulnerability identifier: #VU110694
CSH Severity: Medium
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-40908
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to overwrite arbitrary files on the system.

The vulnerability exists due to insufficient validation of user-supplied input in LoadFile method. A remote attacker can pass specially crafted arguments to the affected method and overwrite arbitrary files on the system. 


Affected software

YAML-LibYAML
Gentoo Linux
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
Anolis OS
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Development Tools Module
openSUSE Leap
openEuler
Ubuntu
perl-YAML-LibYAML-debuginfo
perl-YAML-LibYAML
perl-YAML-LibYAML-debugsource
perl-YAML-LibYAML (Red Hat package)
libyaml-libyaml-perl (Ubuntu package)
perl-YAML-LibYAML-help
perl-YAML-LibYAML-tests
perl-YAML-LibYAML-doc
dev-perl/YAML-LibYAML

How to mitigate CVE-2025-40908

Install updates from vendor's website.

YAML-LibYAML - update to 0.903.0
perl-YAML-LibYAML-debuginfo - addressed in versions 0.38-11.3.1, 0.890.0-150000.3.11.1, 0.904.0-150000.3.16.1
perl-YAML-LibYAML - addressed in versions 0.38-11.3.1, 0.890.0-150000.3.11.1, 0.904.0-150000.3.16.1
perl-YAML-LibYAML-debugsource - addressed in versions 0.38-11.3.1, 0.890.0-150000.3.11.1, 0.904.0-150000.3.16.1
perl-YAML-LibYAML - addressed in versions 0.70-2, 0.86-2
perl-YAML-LibYAML (Red Hat package) - addressed in versions 0.70-2.el8_10, 0.82-6.el9_4.1
libyaml-libyaml-perl (Ubuntu package) - addressed in versions 0.83+ds-1ubuntu0.22.04.1, 0.89+ds-1ubuntu0.24.04.1
perl-YAML-LibYAML-debuginfo - update to 0.83-2
perl-YAML-LibYAML-help - update to 0.83-2
perl-YAML-LibYAML-debugsource - update to 0.83-2
perl-YAML-LibYAML - update to 0.83-2
perl-YAML-LibYAML-tests - update to 0.86-2
perl-YAML-LibYAML-doc - update to 0.86-2
dev-perl/YAML-LibYAML - update to 0.903.0

External References

Related Security Bulletins