Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:8677 - Security Advisory
Issued:
2025-06-09
Updated:
2025-06-09

RHSA-2025:8677 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: perl-FCGI security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for perl-FCGI is now available for Red Hat Enterprise Linux 9.4 Extended Update Support.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

FastCGI Perl bindings.

Security Fix(es):

  • perl-fcgi: FCGI versions 0.44 through 0.82, for Perl, include a vulnerable version of the FastCGI fcgi2 (aka fcgi) library (CVE-2025-40907)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.4 x86_64
  • Red Hat Enterprise Linux Server - AUS 9.4 x86_64
  • Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.4 s390x
  • Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.4 ppc64le
  • Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.4 aarch64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.4 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4 x86_64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.4 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.4 s390x

Fixes

  • BZ - 2366847 - CVE-2025-40907 perl-fcgi: FCGI versions 0.44 through 0.82, for Perl, include a vulnerable version of the FastCGI fcgi2 (aka fcgi) library

CVEs

  • CVE-2025-40907

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.4

SRPM
perl-FCGI-0.79-8.el9_4.1.src.rpm SHA-256: aade006b970989b9e45e6835c3472257881475b46778b7383249ebdb29662d6c
x86_64
perl-FCGI-0.79-8.el9_4.1.x86_64.rpm SHA-256: 94b6ce63c91d826d16efff32c2152ca4a3457aa0b7c765c32400382e4055ed5d
perl-FCGI-debuginfo-0.79-8.el9_4.1.x86_64.rpm SHA-256: 4e51de2f1e6fec8fc3757a9b2bcb0c0e4fca79d0f9eb80b410d5ab142cf48703
perl-FCGI-debugsource-0.79-8.el9_4.1.x86_64.rpm SHA-256: 4877dc5f7b3e35b584c215fadd0837b57686a16ba371bf89ccdd77f98308d20f

Red Hat Enterprise Linux Server - AUS 9.4

SRPM
perl-FCGI-0.79-8.el9_4.1.src.rpm SHA-256: aade006b970989b9e45e6835c3472257881475b46778b7383249ebdb29662d6c
x86_64
perl-FCGI-0.79-8.el9_4.1.x86_64.rpm SHA-256: 94b6ce63c91d826d16efff32c2152ca4a3457aa0b7c765c32400382e4055ed5d
perl-FCGI-debuginfo-0.79-8.el9_4.1.x86_64.rpm SHA-256: 4e51de2f1e6fec8fc3757a9b2bcb0c0e4fca79d0f9eb80b410d5ab142cf48703
perl-FCGI-debugsource-0.79-8.el9_4.1.x86_64.rpm SHA-256: 4877dc5f7b3e35b584c215fadd0837b57686a16ba371bf89ccdd77f98308d20f

Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.4

SRPM
perl-FCGI-0.79-8.el9_4.1.src.rpm SHA-256: aade006b970989b9e45e6835c3472257881475b46778b7383249ebdb29662d6c
s390x
perl-FCGI-0.79-8.el9_4.1.s390x.rpm SHA-256: 9fcdb6d8eff1756c6ce5f8b974a4454ffe3a237f2c71a27c62a37322519140ea
perl-FCGI-debuginfo-0.79-8.el9_4.1.s390x.rpm SHA-256: b47cb811f04f1feaa227b1f5d1d8c5ea0a87bed29de4df22d80cb2bedb8fd5e3
perl-FCGI-debugsource-0.79-8.el9_4.1.s390x.rpm SHA-256: f8cdc2c0c7aed64d701337512127979cd7107329016ba5d7ac9aa7c460a47221

Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.4

SRPM
perl-FCGI-0.79-8.el9_4.1.src.rpm SHA-256: aade006b970989b9e45e6835c3472257881475b46778b7383249ebdb29662d6c
ppc64le
perl-FCGI-0.79-8.el9_4.1.ppc64le.rpm SHA-256: 6431c5df264608cac5387799531402147919afee7e8a9499d180e77c542189d7
perl-FCGI-debuginfo-0.79-8.el9_4.1.ppc64le.rpm SHA-256: ce0e80f561d2b4483367d6e62aa8930d669b983ab7e8f115ef8f0f3c06bf1943
perl-FCGI-debugsource-0.79-8.el9_4.1.ppc64le.rpm SHA-256: 39db8542624b44bded3cee266adbe62260382527363b87b5877ff519a2cac233

Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.4

SRPM
perl-FCGI-0.79-8.el9_4.1.src.rpm SHA-256: aade006b970989b9e45e6835c3472257881475b46778b7383249ebdb29662d6c
aarch64
perl-FCGI-0.79-8.el9_4.1.aarch64.rpm SHA-256: ab60edb1ecd53c008b359b797a6ee69d8581e9934b0547cdfea783736ceee600
perl-FCGI-debuginfo-0.79-8.el9_4.1.aarch64.rpm SHA-256: acd7bfd444a3407d4763dc66bc8df3265745ff3479a6aa625e50d585d99b9ea4
perl-FCGI-debugsource-0.79-8.el9_4.1.aarch64.rpm SHA-256: 1eb9b4843ae083dd7f728b089f9c2ab4e4834718fc3280e516f1341bae687992

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.4

SRPM
perl-FCGI-0.79-8.el9_4.1.src.rpm SHA-256: aade006b970989b9e45e6835c3472257881475b46778b7383249ebdb29662d6c
ppc64le
perl-FCGI-0.79-8.el9_4.1.ppc64le.rpm SHA-256: 6431c5df264608cac5387799531402147919afee7e8a9499d180e77c542189d7
perl-FCGI-debuginfo-0.79-8.el9_4.1.ppc64le.rpm SHA-256: ce0e80f561d2b4483367d6e62aa8930d669b983ab7e8f115ef8f0f3c06bf1943
perl-FCGI-debugsource-0.79-8.el9_4.1.ppc64le.rpm SHA-256: 39db8542624b44bded3cee266adbe62260382527363b87b5877ff519a2cac233

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4

SRPM
perl-FCGI-0.79-8.el9_4.1.src.rpm SHA-256: aade006b970989b9e45e6835c3472257881475b46778b7383249ebdb29662d6c
x86_64
perl-FCGI-0.79-8.el9_4.1.x86_64.rpm SHA-256: 94b6ce63c91d826d16efff32c2152ca4a3457aa0b7c765c32400382e4055ed5d
perl-FCGI-debuginfo-0.79-8.el9_4.1.x86_64.rpm SHA-256: 4e51de2f1e6fec8fc3757a9b2bcb0c0e4fca79d0f9eb80b410d5ab142cf48703
perl-FCGI-debugsource-0.79-8.el9_4.1.x86_64.rpm SHA-256: 4877dc5f7b3e35b584c215fadd0837b57686a16ba371bf89ccdd77f98308d20f

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.4

SRPM
perl-FCGI-0.79-8.el9_4.1.src.rpm SHA-256: aade006b970989b9e45e6835c3472257881475b46778b7383249ebdb29662d6c
aarch64
perl-FCGI-0.79-8.el9_4.1.aarch64.rpm SHA-256: ab60edb1ecd53c008b359b797a6ee69d8581e9934b0547cdfea783736ceee600
perl-FCGI-debuginfo-0.79-8.el9_4.1.aarch64.rpm SHA-256: acd7bfd444a3407d4763dc66bc8df3265745ff3479a6aa625e50d585d99b9ea4
perl-FCGI-debugsource-0.79-8.el9_4.1.aarch64.rpm SHA-256: 1eb9b4843ae083dd7f728b089f9c2ab4e4834718fc3280e516f1341bae687992

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.4

SRPM
perl-FCGI-0.79-8.el9_4.1.src.rpm SHA-256: aade006b970989b9e45e6835c3472257881475b46778b7383249ebdb29662d6c
s390x
perl-FCGI-0.79-8.el9_4.1.s390x.rpm SHA-256: 9fcdb6d8eff1756c6ce5f8b974a4454ffe3a237f2c71a27c62a37322519140ea
perl-FCGI-debuginfo-0.79-8.el9_4.1.s390x.rpm SHA-256: b47cb811f04f1feaa227b1f5d1d8c5ea0a87bed29de4df22d80cb2bedb8fd5e3
perl-FCGI-debugsource-0.79-8.el9_4.1.s390x.rpm SHA-256: f8cdc2c0c7aed64d701337512127979cd7107329016ba5d7ac9aa7c460a47221

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility