Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Fedora 42: perl-Plack-Middleware-Session Critical CVE-2025-40923 ID Issue

fedora
Calendar Grey September 16, 2025
Dist Fedora Esm H88
The enhancement to perl-Plack-Middleware-Session version 0.36 addresses CVE-2025-40923 by implementing robust session ID creation.
This update upgrade the package to version 0.36

Summary

This is a Plack Middleware component for session management. By default it

will use cookies to keep session state and store data in memory. This

distribution also comes with other state and store solutions.

Update Information:

This update upgrade the package to version 0.36. This version fixes CVE-2025-40923 by using Crypt::SysRandom to generate secure session IDs.

Change Log

* Sun Aug 31 2025 Emmanuel Seyman - 0.36-1 - Update to 0.36

References


[ 1 ] Bug #2381421 - CVE-2025-40923 perl-Plack-Middleware-Session: Plack-Middleware-Session insecure session ids [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2381421

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-ca07c36a0a' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: perl-Plack-Middleware-Session
Product: Fedora 42
Version: 0.36
Release: 1.fc42
Summary: Middleware for session management

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here