Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.dist > #1251690 > unrolled thread

Bug#1108676: unblock/pre-approval: perl / CVE-2025-40909

Started byNiko Tyni <ntyni@debian.org>
First post2025-07-02 22:10 +0200
Last post2025-07-08 16:40 +0200
Articles 3 — 2 participants

Back to article view | Back to linux.debian.bugs.dist


Contents

  Bug#1108676: unblock/pre-approval: perl / CVE-2025-40909 Niko Tyni <ntyni@debian.org> - 2025-07-02 22:10 +0200
    Bug#1108676: unblock/pre-approval: perl / CVE-2025-40909 Ivo De Decker <ivodd@debian.org> - 2025-07-03 14:40 +0200
      Bug#1108676: unblock/pre-approval: perl / CVE-2025-40909 Niko Tyni <ntyni@debian.org> - 2025-07-08 16:40 +0200

#1251690 — Bug#1108676: unblock/pre-approval: perl / CVE-2025-40909

FromNiko Tyni <ntyni@debian.org>
Date2025-07-02 22:10 +0200
SubjectBug#1108676: unblock/pre-approval: perl / CVE-2025-40909
Message-ID<L4bWh-eMZO-1@gated-at.bofh.it>

[Multipart message — attachments visible in raw view] — view raw

Package: release.debian.org
Severity: normal
User: release.debian.org@packages.debian.org
Usertags: unblock
X-Debbugs-Cc: perl@packages.debian.org, perl@packages.debian.org
Control: affects -1 + src:perl

Hi, please consider pre-approving the changes in perl/5.40.1-4
in experimental for sid/trixie.

This fixes #1098226 / CVE-2025-40909, a working directory race condition
during thread creation.

The severity was a bit questionable at first, but it's now considered a
proper security issue. Upstream will be releasing updates for supported
versions (5.40 and I believe 5.38 too). So I think we should follow suit.
I intend to try and fix this later also for bookworm via a point release.

The fix took a while for upstream to get right, so there's three cherry
picked commits as separate patches. Furthermore, the changes to the
top level Configure script needed two other patches so we can keep the
Configure regeneration machinery working. (See #762638 for the background
on why we have this machinery.)

Unfortunately that means the debdiff is a bit cluttered. For your
convenience, I'm also attaching the squashed version of the changes
(output of ` git diff debian/5.40.1-3 debian/5.40.1-4 ':!debian/' `)
as `perl_5.40.1-4.gitdiff`.

I uploaded this to experimental to get the "sid pseudo-excuses" debci
results. I believe we now have those and no regressions were found.

(I'm not quite sure how to confirm the test coverage, as I see no way
to query test results scheduled by others in the ci.debian.net API.
But a manual check of a random sample found successful tests for
all of them.)

I have also tested rebuilding 5331 packages in sid including all reverse
dependencies of perl and all packages matching 'lib.*perl'. I found no
regressions with those either.

If you're OK with acking this, I plan to upload the current version
unchanged expect for an 'upload to unstable' changelog entry as 5.40.1-5.

Thanks for your work on the release,
-- 
Niko

[toc] | [next] | [standalone]


#1251736

FromIvo De Decker <ivodd@debian.org>
Date2025-07-03 14:40 +0200
Message-ID<L4rol-eWNh-15@gated-at.bofh.it>
In reply to#1251690
Control: tags -1 confirmed moreinfo

Hi,

On Wed, Jul 02, 2025 at 11:02:07PM +0300, Niko Tyni wrote:
> Hi, please consider pre-approving the changes in perl/5.40.1-4
> in experimental for sid/trixie.

Please go ahead with the upload and remove the moreinfo tag from this unblock
request once the new upload has been in unstable for a few days, and you think
it's ready to migrate.

Thanks,

Ivo

[toc] | [prev] | [next] | [standalone]


#1252162

FromNiko Tyni <ntyni@debian.org>
Date2025-07-08 16:40 +0200
Message-ID<L6hEd-g8e3-3@gated-at.bofh.it>
In reply to#1251736
Control: tags -1 - moreinfo

On Thu, Jul 03, 2025 at 12:37:23PM +0000, Ivo De Decker wrote:
> Control: tags -1 confirmed moreinfo
> 
> Hi,
> 
> On Wed, Jul 02, 2025 at 11:02:07PM +0300, Niko Tyni wrote:
> > Hi, please consider pre-approving the changes in perl/5.40.1-4
> > in experimental for sid/trixie.
> 
> Please go ahead with the upload and remove the moreinfo tag from this unblock
> request once the new upload has been in unstable for a few days, and you think
> it's ready to migrate.

Thanks, I think we're pretty much there now.
-- 
Niko

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.bugs.dist


csiph-web