Advisories ยป MGASA-2025-0274

Updated perl packages fix security vulnerabilities

Publication date: 12 Nov 2025
Modification date: 12 Nov 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2023-31484 , CVE-2024-56406 , CVE-2025-40909

Description

CPAN.pm before 2.35 does not verify TLS certificates when downloading
distributions over HTTPS. (CVE-2023-31484)
Perl is vulnerable to a heap buffer overflow when transliterating
non-ASCII bytes. (CVE-2024-56406)
Perl threads have a working directory race condition where file
operations may target unintended paths. (CVE-2025-40909)
                

References

SRPMS

9/core