CVE-2025-40909

NameCVE-2025-40909
DescriptionThread creation while a directory handle is open does a fchdir, affecting other threads (race condition)
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1098226

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
perl (PTS)bullseye5.32.1-4+deb11u3vulnerable
bullseye (security)5.32.1-4+deb11u4vulnerable
bookworm, bookworm (security)5.36.0-7+deb12u2vulnerable
sid, trixie5.40.1-3vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
perlsource(unstable)(unfixed)1098226

Notes

[bookworm] - perl <postponed> (Minor issue; decide for DSA or no-DSA once upstream lands a fix)
[bullseye] - perl <postponed> (Minor issue, revisit when fixed upstream)
https://github.com/Perl/perl5/issues/23010

Search for package or bug name: Reporting problems