Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 598
Alerts This Week
Warning Icon 1 598

Ubuntu 24.04 LTS, USN-7632-1 critical: libyaml-libyaml-perl file overwrite

ubuntu
Calendar Grey July 9, 2025
Scroller Ubuntu
Essential patch for Ubuntu targeting security vulnerabilities in libyaml-libyaml-perl, impacting various LTS editions.
YAML-LibYAML could be made to overwrite files.

Summary

YAML-LibYAML could be made to overwrite files.

Software Description:

- libyaml-libyaml-perl: Perl interface to libyaml, a YAML implementation

Details:

It was discovered that YAML-LibYAML incorrectly handled certain file

names. An attacker could possibly use this issue to overwrite arbitrary

files.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 24.04 LTS
  libyaml-libyaml-perl            0.89+ds-1ubuntu0.24.04.1

Ubuntu 22.04 LTS
  libyaml-libyaml-perl            0.83+ds-1ubuntu0.22.04.1

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-7632-1

CVE-2025-40908

Severity
critical
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-7632-1

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.