CVE-2025-40909
published 2025-05-30CVE-2025-40909: Perl threads have a working directory race condition where file operations may target unintended paths. If a directory handle is open at thread creation, the…
PriorityP428medium5.9CVSS 3.1
AVLACLPRNUINSUCLILAL
EPSS
0.37%
29.6th percentile
Perl threads have a working directory race condition where file operations may target unintended paths.
If a directory handle is open at thread creation, the process-wide current working directory is temporarily changed in order to clone that handle for the new thread, which is visible from any third (or more) thread already running.
This may lead to unintended operations such as loading code or accessing files from unexpected locations, which a local attacker may be able to exploit.
The bug was introduced in commit 11a11ecf4bea72b17d250cfb43c897be1341861e and released in Perl version 5.13.6
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos_sequoia | — | — |
| apple | macos_sonoma | — | — |
| apple | macos_tahoe | — | — |
| debian | perl | < perl 5.36.0-7+deb12u3 (bookworm) | perl 5.36.0-7+deb12u3 (bookworm) |
| msrc | azl3_perl_5.38.2-509_on_azure_linux_3.0 | — | — |
| msrc | cbl2_perl_5.34.1-491_on_cbl_mariner_2.0 | — | — |
| msrc | cm2_perl_5.34.1-491_on_cbl_mariner_2.0 | — | — |
| perl | perl | >= 0 < 5.36.0-7+deb12u3 | 5.36.0-7+deb12u3 |
| perl | perl | >= 0 < 5.40.1-5 | 5.40.1-5 |
| perl | perl | >= 0 < 5.40.1-5 | 5.40.1-5 |
| perl | perl | >= 5.13.6 < 5.41.13 | 5.41.13 |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_msrc5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2025-40909: macOS Sonoma 14.8
vendor_apple·2025-09-15·CVSS 5.9
CVE-2025-40909 [MEDIUM] CVE-2025-40909: macOS Sonoma 14.8
Apple Security Update: About the security content of macOS Sonoma 14.8
Product: macOS Sonoma
Version: 14.8
CVE: CVE-2025-40909
Component: CVE-2025-40909
Apple
CVE-2025-40909: macOS Tahoe 26
vendor_apple·2025-09-15·CVSS 5.9
CVE-2025-40909 [MEDIUM] CVE-2025-40909: macOS Tahoe 26
Apple Security Update: About the security content of macOS Tahoe 26
Product: macOS Tahoe
Version: 26
CVE: CVE-2025-40909
Component: CVE-2025-40909
Apple
CVE-2025-40909: macOS Sequoia 15.7
vendor_apple·2025-09-15·CVSS 5.9
CVE-2025-40909 [MEDIUM] CVE-2025-40909: macOS Sequoia 15.7
Apple Security Update: About the security content of macOS Sequoia 15.7
Product: macOS Sequoia
Version: 15.7
CVE: CVE-2025-40909
Component: CVE-2025-40909
Ubuntu
Perl vulnerability
vendor_ubuntu·2025-07-29
CVE-2025-40909 Perl vulnerability
Title: Perl vulnerability
Summary: Perl could be made to target unintended paths when performing file
operations.
It was discovered that Perl threads incorrectly handled certain file
operations. A local attacker could possibly use this issue to load code or
access files from unexpected locations.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
perl: Perl threads have a working directory race condition where file operations may target unintended paths
vendor_redhat·2025-05-30·CVSS 5.9
CVE-2025-40909 [MEDIUM] CWE-427 perl: Perl threads have a working directory race condition where file operations may target unintended paths
perl: Perl threads have a working directory race condition where file operations may target unintended paths
Perl threads have a working directory race condition where file operations may target unintended paths.
If a directory handle is open at thread creation, the process-wide current working directory is temporarily changed in order to clone that handle for the new thread, which is visible from any third (or more) thread already running.
This may lead to unintended operations such as loading code or accessing files from unexpected locations, which a local attacker may be able to exploit.
The bug was introduced in commit 11a11ecf4bea72b17d250cfb43c897be1341861e and released in Perl version 5.13.6
A flaw was found in the Perl standard library threads component. This vulnerability can al
Microsoft
Perl threads have a working directory race condition where file operations may target unintended paths
vendor_msrc·2025-05-13·CVSS 5.9
CVE-2025-40909 [MEDIUM] CWE-362 Perl threads have a working directory race condition where file operations may target unintended paths
Perl threads have a working directory race condition where file operations may target unintended paths
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
CPANSec: CPANSec
Customer Action Required: Yes
Remediat
Debian
CVE-2025-40909: perl - Perl threads have a working directory race condition where file operations may t...
vendor_debian·2025·CVSS 5.9
CVE-2025-40909 [MEDIUM] CVE-2025-40909: perl - Perl threads have a working directory race condition where file operations may t...
Perl threads have a working directory race condition where file operations may target unintended paths. If a directory handle is open at thread creation, the process-wide current working directory is temporarily changed in order to clone that handle for the new thread, which is visible from any third (or more) thread already running. This may lead to unintended operations such as loading code or accessing files from unexpected locations, which a local attacker may be able to exploit. The bug was introduced in commit 11a11ecf4bea72b17d250cfb43c897be1341861e and released in Perl version 5.13.6
Scope: local
bookworm: resolved (fixed in 5.36.0-7+deb12u3)
bullseye: open
forky: resolved (fixed in 5.40.1-5)
sid: resolved (fixed in 5.40.1-5)
trixie: resolved (fixed in 5.40.1-5)
GHSA
GHSA-jpf5-526x-c5hw: Perl threads have a working directory race condition where file operations may target unintended paths
ghsa_unreviewed·2025-05-30
CVE-2025-40909 [MEDIUM] CWE-362 GHSA-jpf5-526x-c5hw: Perl threads have a working directory race condition where file operations may target unintended paths
Perl threads have a working directory race condition where file operations may target unintended paths.
If a directory handle is open at thread creation, the process-wide current working directory is temporarily changed in order to clone that handle for the new thread, which is visible from any third (or more) thread already running.
This may lead to unintended operations such as loading code or accessing files from unexpected locations, which a local attacker may be able to exploit.
The bug was introduced in commit 11a11ecf4bea72b17d250cfb43c897be1341861e and released in Perl version 5.13.6
OSV
CVE-2025-40909: Perl threads have a working directory race condition where file operations may target unintended paths
osv·2025-05-30·CVSS 5.9
CVE-2025-40909 [MEDIUM] CVE-2025-40909: Perl threads have a working directory race condition where file operations may target unintended paths
Perl threads have a working directory race condition where file operations may target unintended paths. If a directory handle is open at thread creation, the process-wide current working directory is temporarily changed in order to clone that handle for the new thread, which is visible from any third (or more) thread already running. This may lead to unintended operations such as loading code or accessing files from unexpected locations, which a local attacker may be able to exploit. The bug was introduced in commit 11a11ecf4bea72b17d250cfb43c897be1341861e and released in Perl version 5.13.6
No detection rules found.
No public exploits indexed.
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1098226https://github.com/Perl/perl5/commit/11a11ecf4bea72b17d250cfb43c897be1341861ehttps://github.com/Perl/perl5/commit/918bfff86ca8d6d4e4ec5b30994451e0bd74aba9.patchhttps://github.com/Perl/perl5/issues/10387https://github.com/Perl/perl5/issues/23010https://perldoc.perl.org/5.14.0/perl5136delta#Directory-handles-not-copied-to-threadshttps://www.openwall.com/lists/oss-security/2025/05/22/2http://seclists.org/fulldisclosure/2025/Sep/53http://seclists.org/fulldisclosure/2025/Sep/54http://seclists.org/fulldisclosure/2025/Sep/55http://www.openwall.com/lists/oss-security/2025/05/23/1http://www.openwall.com/lists/oss-security/2025/05/30/4http://www.openwall.com/lists/oss-security/2025/06/02/2http://www.openwall.com/lists/oss-security/2025/06/02/5http://www.openwall.com/lists/oss-security/2025/06/02/6http://www.openwall.com/lists/oss-security/2025/06/02/7http://www.openwall.com/lists/oss-security/2025/06/03/1https://lists.debian.org/debian-lts-announce/2026/04/msg00018.html
2025-05-30
Published