perl-XML-LibXML-2.0132-3.el8_10

エラータID: AXSA:2026-1285:01

Release date: 
Sunday, July 19, 2026 - 11:59
Subject: 
perl-XML-LibXML-2.0132-3.el8_10
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
High
Description: 

This module implements a Perl interface to the GNOME libxml2 library which provides interfaces for parsing and manipulating XML files. This module allows Perl programmers to make use of the highly capable validating XML parser and the high performance DOM implementation.

Security Fix(es):

* perl-XML-LibXML: XML::LibXML: Denial of Service via truncated UTF-8 in XML node names (CVE-2026-8177)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-8177
XML::LibXML versions through 2.0210 for Perl read out-of-bounds heap memory when parsing XML node names containing truncated UTF-8 byte sequences. A node name ending in the middle of a multi byte UTF-8 sequence causes the parser to read past the end of the input string into adjacent heap memory. Any Perl process that passes attacker controlled strings to XML::LibXML's DOM node-name methods can reach this path on the default API. The likely consequence is a crash, causing denial of service.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. perl-XML-LibXML-2.0132-3.el8_10.src.rpm
    MD5: 1970496d8c221e1f151a51d014919d1f
    SHA-256: 0a25c26bafd7458c562b7c72872d667b05246859e2dc19fb21e9c32b5c676a5a
    Size: 486.50 kB

Asianux Server 8 for x86_64
  1. perl-XML-LibXML-2.0132-3.el8_10.i686.rpm
    MD5: 4139a507b14c16fed2a88e885f46b3bd
    SHA-256: e5cd2ea0f90b5811b6656d04597edf05682498a8ded721a377f4cf25fcf9233b
    Size: 390.98 kB
  2. perl-XML-LibXML-2.0132-3.el8_10.x86_64.rpm
    MD5: a1f972f0aab02ace373ee4fd9b47d707
    SHA-256: b96149dac0d8e414bed5b46c92d83220607437fc70d072f718ebeb40d09bdda8
    Size: 370.75 kB