<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 10:22:05 +0000</lastBuildDate>
    <item>
      <title>ALSA-2025:11805 — Moderate: perl security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2025:11805</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: perl, AlmaLinux:8: perl-Attribute-Handlers, AlmaLinux:8: perl-Devel-Peek, AlmaLinux:8: perl-Devel-SelfStubber, AlmaLinux:8: perl-Errno, AlmaLinux:8: perl-ExtUtils-Embed, AlmaLinux:8: perl-ExtUtils-Miniperl, AlmaLinux:8: perl-IO, AlmaLinux:8: perl-IO-Zlib, AlmaLinux:8: perl-Locale-Maketext-Simple and 16 more&lt;/p&gt;
&lt;p&gt;Perl is a high-level programming language that is commonly used for system administration utilities and web programming.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* perl: Perl threads have a working directory race condition where file operations may target unintended paths (CVE-2025-40909)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: perl, AlmaLinux:8: perl-Attribute-Handlers, AlmaLinux:8: perl-Devel-Peek, AlmaLinux:8: perl-Devel-SelfStubber, AlmaLinux:8: perl-Errno, AlmaLinux:8: perl-ExtUtils-Embed, AlmaLinux:8: perl-ExtUtils-Miniperl, AlmaLinux:8: perl-IO, AlmaLinux:8: perl-IO-Zlib, AlmaLinux:8: perl-Locale-Maketext-Simple and 16 more&lt;/p&gt;
&lt;p&gt;Perl is a high-level programming language that is commonly used for system administration utilities and web programming.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* perl: Perl threads have a working directory race condition where file operations may target unintended paths (CVE-2025-40909)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2025:11805</guid>
    </item>
    <item>
      <title>bdu:2025-10307</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-10307</link>
      <description>bdu:2025-10307</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-10307</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-40909</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-40909</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: perl, Alpaquita:stream: perl, BellSoft Hardened Containers:23: perl, BellSoft Hardened Containers:stream: perl&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: perl, Alpaquita:stream: perl, BellSoft Hardened Containers:23: perl, BellSoft Hardened Containers:stream: perl&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-40909</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0756 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0756</link>
      <description>certfr-2025-avi-0756</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0756</guid>
    </item>
    <item>
      <title>EUVD-2026-291906</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-291906</link>
      <description>EUVD-2026-291906</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-291906</guid>
    </item>
    <item>
      <title>fkie_cve-2025-40909</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-40909</link>
      <description>&lt;p&gt;Perl threads have a working directory race condition where file operations may target unintended paths.&lt;/p&gt;
&lt;p&gt;If a directory handle is open at thread creation, the process-wide current working directory is temporarily changed in order to clone that handle for the new thread, which is visible from any third (or more) thread already running.&lt;/p&gt;
&lt;p&gt;This may lead to unintended operations such as loading code or accessing files from unexpected locations, which a local attacker may be able to exploit.&lt;/p&gt;
&lt;p&gt;The bug was introduced in commit 11a11ecf4bea72b17d250cfb43c897be1341861e and released in Perl version 5.13.6&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Perl threads have a working directory race condition where file operations may target unintended paths.&lt;/p&gt;
&lt;p&gt;If a directory handle is open at thread creation, the process-wide current working directory is temporarily changed in order to clone that handle for the new thread, which is visible from any third (or more) thread already running.&lt;/p&gt;
&lt;p&gt;This may lead to unintended operations such as loading code or accessing files from unexpected locations, which a local attacker may be able to exploit.&lt;/p&gt;
&lt;p&gt;The bug was introduced in commit 11a11ecf4bea72b17d250cfb43c897be1341861e and released in Perl version 5.13.6&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-40909</guid>
    </item>
    <item>
      <title>GHSA-jpf5-526x-c5hw</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jpf5-526x-c5hw</link>
      <description>&lt;p&gt;Perl threads have a working directory race condition where file operations may target unintended paths.&lt;/p&gt;
&lt;p&gt;If a directory handle is open at thread creation, the process-wide current working directory is temporarily changed in order to clone that handle for the new thread, which is visible from any third (or more) thread already running.&lt;/p&gt;
&lt;p&gt;This may lead to unintended operations such as loading code or accessing files from unexpected locations, which a local attacker may be able to exploit.&lt;/p&gt;
&lt;p&gt;The bug was introduced in commit 11a11ecf4bea72b17d250cfb43c897be1341861e and released in Perl version 5.13.6&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Perl threads have a working directory race condition where file operations may target unintended paths.&lt;/p&gt;
&lt;p&gt;If a directory handle is open at thread creation, the process-wide current working directory is temporarily changed in order to clone that handle for the new thread, which is visible from any third (or more) thread already running.&lt;/p&gt;
&lt;p&gt;This may lead to unintended operations such as loading code or accessing files from unexpected locations, which a local attacker may be able to exploit.&lt;/p&gt;
&lt;p&gt;The bug was introduced in commit 11a11ecf4bea72b17d250cfb43c897be1341861e and released in Perl version 5.13.6&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jpf5-526x-c5hw</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-40909 — Perl threads have a working directory race condition where file operations may target unintended paths</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-40909</link>
      <description>msrc_CVE-2025-40909</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-40909</guid>
    </item>
    <item>
      <title>OESA-2025-1631 — perl security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-1631</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: perl, openEuler:22.03-LTS-SP3: perl, openEuler:22.03-LTS-SP4: perl, openEuler:24.03-LTS: perl, openEuler:24.03-LTS-SP1: perl&lt;/p&gt;
&lt;p&gt;Perl 5 is a highly capable, feature-rich programming language with over 30 years of development. Perl 5 runs on over 100 platforms from portables to mainframes and is suitable for both rapid prototyping and large scale development projects.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Perl threads have a working directory race condition where file operations may target unintended paths.&lt;/p&gt;
&lt;p&gt;If a directory handle is open at thread creation, the process-wide current working directory is temporarily changed in order to clone that handle for the new thread, which is visible from any third (or more) thread already running.&lt;/p&gt;
&lt;p&gt;This may lead to unintended operations such as loading code or accessing files from unexpected locations, which a local attacker may be able to exploit.&lt;/p&gt;
&lt;p&gt;The bug was introduced in commit 11a11ecf4bea72b17d250cfb43c897be1341861e and released in Perl version 5.13.6(CVE-2025-40909)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: perl, openEuler:22.03-LTS-SP3: perl, openEuler:22.03-LTS-SP4: perl, openEuler:24.03-LTS: perl, openEuler:24.03-LTS-SP1: perl&lt;/p&gt;
&lt;p&gt;Perl 5 is a highly capable, feature-rich programming language with over 30 years of development. Perl 5 runs on over 100 platforms from portables to mainframes and is suitable for both rapid prototyping and large scale development projects.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Perl threads have a working directory race condition where file operations may target unintended paths.&lt;/p&gt;
&lt;p&gt;If a directory handle is open at thread creation, the process-wide current working directory is temporarily changed in order to clone that handle for the new thread, which is visible from any third (or more) thread already running.&lt;/p&gt;
&lt;p&gt;This may lead to unintended operations such as loading code or accessing files from unexpected locations, which a local attacker may be able to exploit.&lt;/p&gt;
&lt;p&gt;The bug was introduced in commit 11a11ecf4bea72b17d250cfb43c897be1341861e and released in Perl version 5.13.6(CVE-2025-40909)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-1631</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15258-1 — perl-32bit-5.40.2-3.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15258-1</link>
      <description>&lt;p&gt;perl-32bit-5.40.2-3.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;perl-32bit-5.40.2-3.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15258-1</guid>
    </item>
    <item>
      <title>RHSA-2025:11545 — Red Hat Security Advisory: perl security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:11545</link>
      <description>&lt;p&gt;perl: Perl threads have a working directory race condition where file operations may target unintended paths&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;perl: Perl threads have a working directory race condition where file operations may target unintended paths&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:11545</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:02051-1 — Security update for perl</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:02051-1</link>
      <description>&lt;p&gt;Security update for perl&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for perl&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:02051-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-40909</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-40909</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: perl, Ubuntu:Pro:16.04:LTS: perl, Ubuntu:Pro:18.04:LTS: perl, Ubuntu:Pro:20.04:LTS: perl, Ubuntu:22.04:LTS: perl, Ubuntu:24.04:LTS: perl&lt;/p&gt;
&lt;p&gt;Perl threads have a working directory race condition where file operations may target unintended paths. If a directory handle is open at thread creation, the process-wide current working directory is temporarily changed in order to clone that handle for the new thread, which is visible from any third (or more) thread already running. This may lead to unintended operations such as loading code or accessing files from unexpected locations, which a local attacker may be able to exploit. The bug was introduced in commit 11a11ecf4bea72b17d250cfb43c897be1341861e and released in Perl version 5.13.6&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: perl, Ubuntu:Pro:16.04:LTS: perl, Ubuntu:Pro:18.04:LTS: perl, Ubuntu:Pro:20.04:LTS: perl, Ubuntu:22.04:LTS: perl, Ubuntu:24.04:LTS: perl&lt;/p&gt;
&lt;p&gt;Perl threads have a working directory race condition where file operations may target unintended paths. If a directory handle is open at thread creation, the process-wide current working directory is temporarily changed in order to clone that handle for the new thread, which is visible from any third (or more) thread already running. This may lead to unintended operations such as loading code or accessing files from unexpected locations, which a local attacker may be able to exploit. The bug was introduced in commit 11a11ecf4bea72b17d250cfb43c897be1341861e and released in Perl version 5.13.6&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-40909</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1206 — Perl: Schwachstelle ermöglicht Codeausführung und Offenlegung von Informationen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1206</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in Perl ausnutzen, um beliebigen Programmcode auszuführen, und um Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in Perl ausnutzen, um beliebigen Programmcode auszuführen, und um Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1206</guid>
    </item>
  </channel>
</rss>
