<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T07:45:07.741592+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2025:11805</id>
    <title>ALSA-2025:11805 — Moderate: perl security update</title>
    <updated>2026-10-03T07:45:08.077859+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: perl, AlmaLinux:8: perl-Attribute-Handlers, AlmaLinux:8: perl-Devel-Peek, AlmaLinux:8: perl-Devel-SelfStubber, AlmaLinux:8: perl-Errno, AlmaLinux:8: perl-ExtUtils-Embed, AlmaLinux:8: perl-ExtUtils-Miniperl, AlmaLinux:8: perl-IO, AlmaLinux:8: perl-IO-Zlib, AlmaLinux:8: perl-Locale-Maketext-Simple and 16 more</p>
<p>Perl is a high-level programming language that is commonly used for system administration utilities and web programming.</p>
<p>Security Fix(es):</p>
<p>* perl: Perl threads have a working directory race condition where file operations may target unintended paths (CVE-2025-40909)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2025:11805"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-10307</id>
    <title>bdu:2025-10307</title>
    <updated>2026-10-03T07:45:08.077959+00:00</updated>
    <content>bdu:2025-10307</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-10307"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-40909</id>
    <title>BELL-CVE-2025-40909</title>
    <updated>2026-10-03T07:45:08.077977+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: perl, Alpaquita:stream: perl, BellSoft Hardened Containers:23: perl, BellSoft Hardened Containers:stream: perl</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-40909"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0756</id>
    <title>certfr-2025-avi-0756 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
    <updated>2026-10-03T07:45:08.078001+00:00</updated>
    <content>certfr-2025-avi-0756</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0756"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-291906</id>
    <title>EUVD-2026-291906</title>
    <updated>2026-10-03T07:45:08.078016+00:00</updated>
    <content>EUVD-2026-291906</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-291906"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-40909</id>
    <title>fkie_cve-2025-40909</title>
    <updated>2026-10-03T07:45:08.078027+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Perl threads have a working directory race condition where file operations may target unintended paths.</p>
<p>If a directory handle is open at thread creation, the process-wide current working directory is temporarily changed in order to clone that handle for the new thread, which is visible from any third (or more) thread already running.</p>
<p>This may lead to unintended operations such as loading code or accessing files from unexpected locations, which a local attacker may be able to exploit.</p>
<p>The bug was introduced in commit 11a11ecf4bea72b17d250cfb43c897be1341861e and released in Perl version 5.13.6</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-40909"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-jpf5-526x-c5hw</id>
    <title>GHSA-jpf5-526x-c5hw</title>
    <updated>2026-10-03T07:45:08.078054+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Perl threads have a working directory race condition where file operations may target unintended paths.</p>
<p>If a directory handle is open at thread creation, the process-wide current working directory is temporarily changed in order to clone that handle for the new thread, which is visible from any third (or more) thread already running.</p>
<p>This may lead to unintended operations such as loading code or accessing files from unexpected locations, which a local attacker may be able to exploit.</p>
<p>The bug was introduced in commit 11a11ecf4bea72b17d250cfb43c897be1341861e and released in Perl version 5.13.6</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-jpf5-526x-c5hw"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-40909</id>
    <title>msrc_CVE-2025-40909 — Perl threads have a working directory race condition where file operations may target unintended paths</title>
    <updated>2026-10-03T07:45:08.078073+00:00</updated>
    <content>msrc_CVE-2025-40909</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-40909"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-1631</id>
    <title>OESA-2025-1631 — perl security update</title>
    <updated>2026-10-03T07:45:08.078089+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP4: perl, openEuler:22.03-LTS-SP3: perl, openEuler:22.03-LTS-SP4: perl, openEuler:24.03-LTS: perl, openEuler:24.03-LTS-SP1: perl</p>
<p>Perl 5 is a highly capable, feature-rich programming language with over 30 years of development. Perl 5 runs on over 100 platforms from portables to mainframes and is suitable for both rapid prototyping and large scale development projects.

Security Fix(es):</p>
<p>Perl threads have a working directory race condition where file operations may target unintended paths.</p>
<p>If a directory handle is open at thread creation, the process-wide current working directory is temporarily changed in order to clone that handle for the new thread, which is visible from any third (or more) thread already running.</p>
<p>This may lead to unintended operations such as loading code or accessing files from unexpected locations, which a local attacker may be able to exploit.</p>
<p>The bug was introduced in commit 11a11ecf4bea72b17d250cfb43c897be1341861e and released in Perl version 5.13.6(CVE-2025-40909)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-1631"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15258-1</id>
    <title>openSUSE-SU-2025:15258-1 — perl-32bit-5.40.2-3.1 on GA media</title>
    <updated>2026-10-03T07:45:08.078122+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>perl-32bit-5.40.2-3.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15258-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:11545</id>
    <title>RHSA-2025:11545 — Red Hat Security Advisory: perl security update</title>
    <updated>2026-10-03T07:45:08.078138+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>perl: Perl threads have a working directory race condition where file operations may target unintended paths</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:11545"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:02051-1</id>
    <title>SUSE-SU-2025:02051-1 — Security update for perl</title>
    <updated>2026-10-03T07:45:08.078153+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for perl</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:02051-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-40909</id>
    <title>UBUNTU-CVE-2025-40909</title>
    <updated>2026-10-03T07:45:08.078168+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: perl, Ubuntu:Pro:16.04:LTS: perl, Ubuntu:Pro:18.04:LTS: perl, Ubuntu:Pro:20.04:LTS: perl, Ubuntu:22.04:LTS: perl, Ubuntu:24.04:LTS: perl</p>
<p>Perl threads have a working directory race condition where file operations may target unintended paths. If a directory handle is open at thread creation, the process-wide current working directory is temporarily changed in order to clone that handle for the new thread, which is visible from any third (or more) thread already running. This may lead to unintended operations such as loading code or accessing files from unexpected locations, which a local attacker may be able to exploit. The bug was introduced in commit 11a11ecf4bea72b17d250cfb43c897be1341861e and released in Perl version 5.13.6</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-40909"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1206</id>
    <title>WID-SEC-W-2025-1206 — Perl: Schwachstelle ermöglicht Codeausführung und Offenlegung von Informationen</title>
    <updated>2026-10-03T07:45:08.078195+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann eine Schwachstelle in Perl ausnutzen, um beliebigen Programmcode auszuführen, und um Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1206"/>
  </entry>
</feed>
