SB2025070757 - Red Hat Enterprise Linux 10 update for yggdrasil
Published: July 7, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2025-3931)
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to the application uses the DBus method to dispatch messages to workers however fails to perform authentication and authorization checks. A local user can create and enable new repositories and install or remove packages.
Remediation
Install update from vendor's website.