NIXPKGS-2025-0006
published on 1 Nov 2025
Permalink
CVE-2025-40928
7.5 HIGH
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): NONE
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): NONE
- Integrity impact (I): NONE
- Availability impact (A): HIGH
by @LeSuisse Activity log
- Created automatic suggestion
-
@LeSuisse
removed
6 packages
- perlPackages.CpanelJSONXS
- perl538Packages.CpanelJSONXS
- perl540Packages.CpanelJSONXS
- perlPackages.JSONXSVersionOneAndTwo
- perl538Packages.JSONXSVersionOneAndTwo
- perl540Packages.JSONXSVersionOneAndTwo
- @LeSuisse accepted
- @LeSuisse published on GitHub
JSON::XS before version 4.04 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspecified impact
JSON::XS before version 4.04 for Perl has an integer buffer overflow causing a segfault when parsing crafted JSON, enabling denial-of-service attacks or other unspecified impact
References
- https://security.metacpan.org/patches/J/JSON-XS/4.03/CVE-2025-40928-r1.patch patch
- https://metacpan.org/release/MLEHMANN/JSON-XS-4.03/source/XS.xs#L256 related
- https://metacpan.org/release/MLEHMANN/JSON-XS-4.03/source/XS.xs#L256 related
- https://security.metacpan.org/patches/J/JSON-XS/4.03/CVE-2025-40928-r1.patch patch
- https://lists.debian.org/debian-lts-announce/2025/09/msg00033.html
- https://metacpan.org/release/MLEHMANN/JSON-XS-4.03/source/XS.xs#L256 related
- https://security.metacpan.org/patches/J/JSON-XS/4.03/CVE-2025-40928-r1.patch patch
- https://lists.debian.org/debian-lts-announce/2025/09/msg00033.html
- http://www.openwall.com/lists/oss-security/2025/09/08/2
Affected products
JSON-XS
- <4.04
Matching in nixpkgs
pkgs.perlPackages.JSONXS
JSON serialising/deserialising, done correctly and fast
-
nixos-unstable -
- nixpkgs-unstable 4.03
pkgs.perl538Packages.JSONXS
JSON serialising/deserialising, done correctly and fast
-
nixos-unstable -
- nixpkgs-unstable 4.03
pkgs.perl540Packages.JSONXS
JSON serialising/deserialising, done correctly and fast
-
nixos-unstable -
- nixpkgs-unstable 4.03