perl-XML-LibXML-2.0206-5.el9_8.1

エラータID: AXSA:2026-1499:02

Release date: 
Monday, August 10, 2026 - 17:39
Subject: 
perl-XML-LibXML-2.0206-5.el9_8.1
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
High
Description: 

This module implements a Perl interface to the GNOME libxml2 library which provides interfaces for parsing and manipulating XML files. This module allows Perl programmers to make use of the highly capable validating XML parser and the high performance DOM implementation.

Security Fix(es):

* perl-XML-LibXML: XML::LibXML: Denial of Service via truncated UTF-8 in XML node names (CVE-2026-8177)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-8177
XML::LibXML versions through 2.0210 for Perl read out-of-bounds heap memory when parsing XML node names containing truncated UTF-8 byte sequences. A node name ending in the middle of a multi byte UTF-8 sequence causes the parser to read past the end of the input string into adjacent heap memory. Any Perl process that passes attacker controlled strings to XML::LibXML's DOM node-name methods can reach this path on the default API. The likely consequence is a crash, causing denial of service.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. perl-XML-LibXML-2.0206-5.el9_8.1.src.rpm
    MD5: 4997107112b1544c83324be4afca2298
    SHA-256: b27426ec6b88ab6fb5e5940cc076b793795d00ec46293818ef19d442614bdd94
    Size: 474.95 kB

Asianux Server 9 for x86_64
  1. perl-XML-LibXML-2.0206-5.el9_8.1.x86_64.rpm
    MD5: 373d6613a2f7bb4746840cc08afb5c22
    SHA-256: ebf04e9844890032a5c4dc3311d90c4fee9a99aa6bc171c688bb3e7145428c8c
    Size: 371.89 kB