RHSA-2026:37070: Moderate: perl:5.32 security update
Moderate: perl:5.32 security update
Other sources
Perl is a high-level programming language that is commonly used for system administration utilities and web programming.Security Fix(es): perl: Perl threads have a working directory race condition where file operations may target unintended paths (CVE-2025-40909) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/perlto a version that resolves this vulnerability.Fixed in 5.32.1-471.module+el8.6.0+24484+7827d5b5.1 - Upgrade
Upgrade
redhat/perl-autodieto a version that resolves this vulnerability.Fixed in 2.34-1.module+el8.6.0+13324+628a2397 - Upgrade
Upgrade
redhat/perl-bignumto a version that resolves this vulnerability.Fixed in 0.51-439.module+el8.6.0+13324+628a2397 - Upgrade
Upgrade
redhat/perl-constantto a version that resolves this vulnerability.Fixed in 1.33-1001.module+el8.6.0+13324+628a2397 - Upgrade
Upgrade
redhat/perl-experimentalto a version that resolves this vulnerability.Fixed in 0.025-1.module+el8.6.0+13324+628a2397 - Upgrade
Upgrade
redhat/perl-generatorsto a version that resolves this vulnerability.Fixed in 1.13-1.module+el8.6.0+13324+628a2397 - Upgrade
Upgrade
redhat/perl-inc-latestto a version that resolves this vulnerability.Fixed in 0.500-10.module+el8.6.0+13324+628a2397 - Upgrade
Upgrade
redhat/perl-libnetto a version that resolves this vulnerability.Fixed in 3.13-1.module+el8.6.0+13324+628a2397 - Upgrade
Upgrade
redhat/perl-local-libto a version that resolves this vulnerability.Fixed in 2.000024-7.module+el8.6.0+13324+628a2397 - Upgrade
Upgrade
redhat/perl-parentto a version that resolves this vulnerability.Fixed in 0.238-457.module+el8.6.0+13324+628a2397 - Upgrade
Upgrade
redhat/perl-perlfaqto a version that resolves this vulnerability.Fixed in 5.20210520-1.module+el8.6.0+13324+628a2397 - Upgrade
Upgrade
redhat/perl-podlatorsto a version that resolves this vulnerability.Fixed in 4.14-457.module+el8.6.0+13324+628a2397 - Upgrade
Upgrade
redhat/perl-threadsto a version that resolves this vulnerability.Fixed in 2.25-457.module+el8.6.0+13324+628a2397 - Upgrade
Upgrade
redhat/perl-threads-sharedto a version that resolves this vulnerability.Fixed in 1.61-457.module+el8.6.0+13324+628a2397 - Upgrade
Upgrade
redhat/perl-versionto a version that resolves this vulnerability.Fixed in 0.99.29-1.module+el8.6.0+13324+628a2397 - Upgrade
Upgrade
redhat/perl-autouseto a version that resolves this vulnerability.Fixed in 1.11-471.module+el8.6.0+24484+7827d5b5.1 - Upgrade
Upgrade
redhat/perl-baseto a version that resolves this vulnerability.Fixed in 2.27-471.module+el8.6.0+24484+7827d5b5.1 - Upgrade
Upgrade
redhat/perl-blibto a version that resolves this vulnerability.Fixed in 1.07-471.module+el8.6.0+24484+7827d5b5.1 - Upgrade
Upgrade
redhat/perl-debuggerto a version that resolves this vulnerability.Fixed in 1.56-471.module+el8.6.0+24484+7827d5b5.1 - Upgrade
Upgrade
redhat/perl-debuginfoto a version that resolves this vulnerability.Fixed in 5.32.1-471.module+el8.6.0+24484+7827d5b5.1 - Upgrade
Upgrade
redhat/perl-debugsourceto a version that resolves this vulnerability.Fixed in 5.32.1-471.module+el8.6.0+24484+7827d5b5.1 - Upgrade
Upgrade
redhat/perl-deprecateto a version that resolves this vulnerability.Fixed in 0.04-471.module+el8.6.0+24484+7827d5b5.1 - Upgrade
Upgrade
redhat/perl-develto a version that resolves this vulnerability.Fixed in 5.32.1-471.module+el8.6.0+24484+7827d5b5.1 - Upgrade
Upgrade
redhat/perl-diagnosticsto a version that resolves this vulnerability.Fixed in 1.37-471.module+el8.6.0+24484+7827d5b5.1 - Upgrade
Upgrade
redhat/perl-docto a version that resolves this vulnerability.Fixed in 5.32.1-471.module+el8.6.0+24484+7827d5b5.1 - Upgrade
Upgrade
redhat/perl-encodingto a version that resolves this vulnerability.Fixed in 3.00-461.module+el8.6.0+13324+628a2397 - Upgrade
Upgrade
redhat/perl-encoding-warningsto a version that resolves this vulnerability.Fixed in 0.13-471.module+el8.6.0+24484+7827d5b5.1 - Upgrade
Upgrade
redhat/perl-fieldsto a version that resolves this vulnerability.Fixed in 2.27-471.module+el8.6.0+24484+7827d5b5.1 - Upgrade
Upgrade
redhat/perl-filetestto a version that resolves this vulnerability.Fixed in 1.03-471.module+el8.6.0+24484+7827d5b5.1 - Upgrade
Upgrade
redhat/perl-homedirto a version that resolves this vulnerability.Fixed in 2.000024-7.module+el8.6.0+13324+628a2397 - Upgrade
Upgrade
redhat/perl-ifto a version that resolves this vulnerability.Fixed in 0.60.800-471.module+el8.6.0+24484+7827d5b5.1 - Upgrade
Upgrade
redhat/perl-interpreterto a version that resolves this vulnerability.Fixed in 5.32.1-471.module+el8.6.0+24484+7827d5b5.1 - Upgrade
Upgrade
redhat/perl-interpreter-debuginfoto a version that resolves this vulnerability.Fixed in 5.32.1-471.module+el8.6.0+24484+7827d5b5.1 - Upgrade
Upgrade
redhat/perl-lessto a version that resolves this vulnerability.Fixed in 0.03-471.module+el8.6.0+24484+7827d5b5.1 - Upgrade
Upgrade
redhat/perl-libto a version that resolves this vulnerability.Fixed in 0.65-471.module+el8.6.0+24484+7827d5b5.1 - Upgrade
Upgrade
redhat/perl-libnetcfgto a version that resolves this vulnerability.Fixed in 5.32.1-471.module+el8.6.0+24484+7827d5b5.1 - Upgrade
Upgrade
redhat/perl-libsto a version that resolves this vulnerability.Fixed in 5.32.1-471.module+el8.6.0+24484+7827d5b5.1 - Upgrade
Upgrade
redhat/perl-libs-debuginfoto a version that resolves this vulnerability.Fixed in 5.32.1-471.module+el8.6.0+24484+7827d5b5.1 - Upgrade
Upgrade
redhat/perl-localeto a version that resolves this vulnerability.Fixed in 1.09-471.module+el8.6.0+24484+7827d5b5.1 - Upgrade
Upgrade
redhat/perl-macrosto a version that resolves this vulnerability.Fixed in 5.32.1-471.module+el8.6.0+24484+7827d5b5.1 - Upgrade
Upgrade
redhat/perl-meta-notationto a version that resolves this vulnerability.Fixed in 5.32.1-471.module+el8.6.0+24484+7827d5b5.1 - Upgrade
Upgrade
redhat/perl-mroto a version that resolves this vulnerability.Fixed in 1.23-471.module+el8.6.0+24484+7827d5b5.1 - Upgrade
Upgrade
redhat/perl-mro-debuginfoto a version that resolves this vulnerability.Fixed in 1.23-471.module+el8.6.0+24484+7827d5b5.1 - Upgrade
Upgrade
redhat/perl-opento a version that resolves this vulnerability.Fixed in 1.12-471.module+el8.6.0+24484+7827d5b5.1 - Upgrade
Upgrade
redhat/perl-overloadto a version that resolves this vulnerability.Fixed in 1.31-471.module+el8.6.0+24484+7827d5b5.1 - Upgrade
Upgrade
redhat/perl-overloadingto a version that resolves this vulnerability.Fixed in 0.02-471.module+el8.6.0+24484+7827d5b5.1 - Upgrade
Upgrade
redhat/perl-phto a version that resolves this vulnerability.Fixed in 5.32.1-471.module+el8.6.0+24484+7827d5b5.1 - Upgrade
Upgrade
redhat/perl-sigtrapto a version that resolves this vulnerability.Fixed in 1.09-471.module+el8.6.0+24484+7827d5b5.1 - Upgrade
Upgrade
redhat/perl-sortto a version that resolves this vulnerability.Fixed in 2.04-471.module+el8.6.0+24484+7827d5b5.1 - Upgrade
Upgrade
redhat/perl-substo a version that resolves this vulnerability.Fixed in 1.03-471.module+el8.6.0+24484+7827d5b5.1 - Upgrade
Upgrade
redhat/perl-threads-debuginfoto a version that resolves this vulnerability.Fixed in 2.25-457.module+el8.6.0+13324+628a2397 - Upgrade
Upgrade
redhat/perl-threads-debugsourceto a version that resolves this vulnerability.Fixed in 2.25-457.module+el8.6.0+13324+628a2397 - Upgrade
Upgrade
redhat/perl-threads-shared-debuginfoto a version that resolves this vulnerability.Fixed in 1.61-457.module+el8.6.0+13324+628a2397 - Upgrade
Upgrade
redhat/perl-threads-shared-debugsourceto a version that resolves this vulnerability.Fixed in 1.61-457.module+el8.6.0+13324+628a2397 - Upgrade
Upgrade
redhat/perl-utilsto a version that resolves this vulnerability.Fixed in 5.32.1-471.module+el8.6.0+24484+7827d5b5.1 - Upgrade
Upgrade
redhat/perl-varsto a version that resolves this vulnerability.Fixed in 1.05-471.module+el8.6.0+24484+7827d5b5.1 - Upgrade
Upgrade
redhat/perl-version-debuginfoto a version that resolves this vulnerability.Fixed in 0.99.29-1.module+el8.6.0+13324+628a2397 - Upgrade
Upgrade
redhat/perl-version-debugsourceto a version that resolves this vulnerability.Fixed in 0.99.29-1.module+el8.6.0+13324+628a2397 - Upgrade
Upgrade
redhat/perl-vmsishto a version that resolves this vulnerability.Fixed in 1.04-471.module+el8.6.0+24484+7827d5b5.1 - Upgrade
Upgrade
perlto a version that resolves this vulnerability.Fixed in 5.32Patch CVE-2025-40909
Event History
Frequently Asked Questions
What is RHSA-2026:37070?
RHSA-2026:37070 is a security update for Perl 5.32 that addresses a race condition in Perl threads.
What is the severity of RHSA-2026:37070?
The severity of RHSA-2026:37070 is classified as medium with a CVSS score of 4.
How do I fix RHSA-2026:37070?
To fix RHSA-2026:37070, users should update their Perl packages to the latest version provided in the security advisory.
What are the main security issues addressed in RHSA-2026:37070?
RHSA-2026:37070 addresses a working directory race condition in Perl threads that could lead to unintended file operations.
Which software packages are affected by RHSA-2026:37070?
The affected software packages in RHSA-2026:37070 include redhat/perl, redhat/perl-autodie, and several others related to Perl.