PT-2025-36473 · Json::Xs+8 · Json::Xs+8

Michael Hudak

·

Published

2025-09-08

·

Updated

2025-11-13

·

CVE-2025-40928

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: JSON::XS versions prior to 4.04
Description: JSON::XS, a Perl module, contains an integer buffer overflow that can lead to a segmentation fault when processing specially crafted JSON data. This issue may result in denial-of-service attacks.
Recommendations: Update JSON::XS to version 4.04 or later.

Fix

DoS

Heap Based Buffer Overflow

Integer Overflow

Weakness Enumeration

Related Identifiers

ALSA-2025:17119
ALSA-2025:17162
ALSA-2025:17163
AZL-67076
AZL-67079
BDU:2025-13160
CESA-2025_17163
CVE-2025-40928
DLA-4317-1
DSA-5999-1
INFSA-2025_17162
INFSA-2025_17163
MGASA-2025-0283
OESA-2025-2365
OESA-2025-2366
OESA-2025-2367
OESA-2025-2447
OESA-2025-2448
OESA-2025-2449
OPENSUSE-SU-2025:15535-1
RHSA-2025:17119
RHSA-2025:17162
RHSA-2025:17163
RHSA-2025:17430
RHSA-2025_17162
RHSA-2025_17163
USN-7750-1

Affected Products

Almalinux
Centos
Debian
Json::Xs
Linuxmint
Red Hat
Red Os
Rocky Linux
Ubuntu