---
title: "CVE-2025-40909\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2025-40909?format=md
keywords: index, follow
---

# CVE-2025-40909

Publication date 30 May 2025

Last updated 29 July 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**5.9 · Medium**

[Score breakdown](https://ubuntu.com/security/CVE-2025-40909?format=md#impact-score)

Toggle side navigation

## Description

Perl threads have a working directory race condition where file operations
may target unintended paths.
If a directory handle is open at thread creation, the process-wide current
working directory is temporarily changed in order to clone that handle for
the new thread, which is visible from any third (or more) thread already
running.
This may lead to unintended operations such as loading code or accessing
files from unexpected locations, which a local attacker may be able to
exploit.
The bug was introduced in commit 11a11ecf4bea72b17d250cfb43c897be1341861e
and released in Perl version 5.13.6

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| perl | 26.04 LTS resolute | Not affected |
| 25.10 questing | Not affected |
| 25.04 plucky | Fixed 5.40.1-2ubuntu0.2 |
| 24.10 oracular | Ignored end of life, was needs-triage |
| 24.04 LTS noble | Fixed 5.38.2-3.2ubuntu0.2 |
| 22.04 LTS jammy | Fixed 5.34.0-3ubuntu1.5 |
| 20.04 LTS focal | Needs evaluation |
| 18.04 LTS bionic | Needs evaluation |
| 16.04 LTS xenial | Needs evaluation |
| 14.04 LTS trusty | Needs evaluation |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2025-40909?format=md#patch-details)

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| perl | * Upstream:   [fc8063a](https://github.com/Perl/perl5/commit/fc8063aa51f400394f2e44173fd4f87f080502c9) * Upstream:   [a1327b5](https://github.com/Perl/perl5/commit/a1327b5df78d0bc1e56b6cff663aa8b508d4e2d6) * Upstream:   [1f9097b](https://github.com/Perl/perl5/commit/1f9097b342e0e37d619dfab6ea82ea99611b30bf) * Upstream:   [5c2e757](https://github.com/Perl/perl5/commit/5c2e7577a3fa70dc39d27c0426db6eb897eee9b1) * Upstream:   [918bfff](https://github.com/Perl/perl5/commit/918bfff86ca8d6d4e4ec5b30994451e0bd74aba9) |

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

5.9 · Medium

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Local |
  | Attack complexity | Low |
  | Privileges required | None |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | Low |
  | Integrity impact | Low |
  | Availability impact | Low |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 5.9 · Medium |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-40909)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2025-40909)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2025-40909)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2025-40909)

### Related Ubuntu Security Notices (USN)

+ [USN-7678-1](https://usn.ubuntu.com/USN-7678-1)
+ Perl vulnerability
+ 29 July 2025

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2025-40909>
* <https://lists.security.metacpan.org/cve-announce/msg/30017499/>
