[ubuntu/noble-security] perl 5.38.2-3.2ubuntu0.2 (Accepted)

Marc Deslauriers marc.deslauriers at canonical.com
Tue Jul 29 12:44:27 UTC 2025


perl (5.38.2-3.2ubuntu0.2) noble-security; urgency=medium

  * SECURITY UPDATE: threads race condition in file operations
    - debian/patches/fixes/CVE-2025-40909-metaconfig.diff: check for
      fdopendir in regen-configure/U/perl/d_fdopendir.U.
    - debian/patches/fixes/CVE-2025-40909-1.diff: clone dirhandles without
      fchdir in Configure, Cross/config.sh-arm-linux,
      Cross/config.sh-arm-linux-n770, Porting/Glossary, Porting/config.sh,
      config_h.SH, configure.com, plan9/config_sh.sample, sv.c,
      t/op/threads-dirh.t, win32/config.gc, win32/config.vc.
    - debian/patches/fixes/CVE-2025-40909-2.diff: minor corrections in
      Cross/config.sh-arm-linux, Cross/config.sh-arm-linux-n770,
      config_h.SH,plan9/config_sh.sample.
    - debian/patches/fixes/CVE-2025-40909-3.diff: use PerlLIO_dup_cloexec
      in Perl_dirp_dup to set O_CLOEXEC in sv.c.
    - debian/patches/fixes/CVE-2025-40909-metaconfig-reorder.diff: slightly
      reorder Configure and config_h.SH to match metaconfig output in
      Configure, config_h.SH.
    - debian/patches/fixes/CVE-2025-40909-generated.diff: update generated
      files and checksums in uconfig.sh, uconfig64.sh, uconfig.h.
    - CVE-2025-40909

Date: 2025-07-26 16:09:14.254692+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/perl/5.38.2-3.2ubuntu0.2
-------------- next part --------------
Sorry, changesfile not available.


More information about the noble-changes mailing list