CVE-2025-40914: Perl CryptX before version 0.087 contains a dependency that may be susceptible to an integer overflow
Published Jun 11, 2025
·Updated
Perl CryptX before version 0.087 contains a dependency that may be susceptible to an integer overflow.
CryptX embeds a version of the libtommath library that is susceptible to an integer overflow associated with CVE-2023-36328.
Affected Software
1 affected component
Perl CryptX<0.087
Remediation
Information
Users should update to version 0.087 or later
Event History
Jun 11, 2025
CVE Published
via MITRE·02:06 PM
Data Sourced
via MITRE·02:06 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2025-40914?
CVE-2025-40914 has not been assigned a severity score, but it is related to a potential integer overflow vulnerability.
2
How do I fix CVE-2025-40914?
To fix CVE-2025-40914, update Perl CryptX to version 0.087 or later, which addresses the underlying dependency issue.
3
What versions of Perl CryptX are affected by CVE-2025-40914?
All versions of Perl CryptX prior to version 0.087 are affected by CVE-2025-40914.
4
What dependency is implicated in CVE-2025-40914?
CVE-2025-40914 implicates the libtommath library, which is embedded within Perl CryptX.
5
Is CVE-2025-40914 related to any other vulnerabilities?
Yes, CVE-2025-40914 is related to CVE-2023-36328, which involves an integer overflow in the libtommath library.