Red Hat Security Advisory: perl-XML-LibXML security update
CVE-2026-8177 is a high-severity vulnerability in the XML::LibXML Perl module that causes an out-of-bounds read of heap memory when parsing XML node names containing truncated UTF-8 byte sequences. This flaw can lead to a crash of the Perl process using the module, resulting in denial of service. The vulnerability affects XML::LibXML versions through 2.0210. Red Hat has released security updates for their Enterprise Linux 9 distributions to address this issue.
AI Analysis
Technical Summary
XML::LibXML versions through 2.0210 for Perl contain an out-of-bounds read vulnerability (CWE-125) triggered by XML node names ending in the middle of a multi-byte UTF-8 sequence. When parsing such malformed node names, the parser reads past the end of the input string into adjacent heap memory, causing a crash. This vulnerability can be reached by any Perl process passing attacker-controlled strings to XML::LibXML's DOM node-name methods using the default API. The primary impact is denial of service due to process crash. Red Hat has issued security advisories and updates for Red Hat Enterprise Linux 9 and 10 to fix this issue.
Potential Impact
The vulnerability allows an attacker to cause a denial of service by crashing Perl processes that use XML::LibXML to parse XML node names containing truncated UTF-8 sequences. There is no indication of confidentiality or integrity impact. No known exploits are reported in the wild at this time.
Mitigation Recommendations
Red Hat has released updated packages for perl-XML-LibXML that fix this vulnerability. Users should apply the security updates provided for Red Hat Enterprise Linux 9 and 10 as detailed in Red Hat advisories RHSA-2026:39553 and RHSA-2026:39547. Patch details and update instructions are available at https://access.redhat.com/articles/11258. Applying these official fixes fully mitigates the issue.
Red Hat Security Advisory: perl-XML-LibXML security update
Description
CVE-2026-8177 is a high-severity vulnerability in the XML::LibXML Perl module that causes an out-of-bounds read of heap memory when parsing XML node names containing truncated UTF-8 byte sequences. This flaw can lead to a crash of the Perl process using the module, resulting in denial of service. The vulnerability affects XML::LibXML versions through 2.0210. Red Hat has released security updates for their Enterprise Linux 9 distributions to address this issue.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
XML::LibXML versions through 2.0210 for Perl contain an out-of-bounds read vulnerability (CWE-125) triggered by XML node names ending in the middle of a multi-byte UTF-8 sequence. When parsing such malformed node names, the parser reads past the end of the input string into adjacent heap memory, causing a crash. This vulnerability can be reached by any Perl process passing attacker-controlled strings to XML::LibXML's DOM node-name methods using the default API. The primary impact is denial of service due to process crash. Red Hat has issued security advisories and updates for Red Hat Enterprise Linux 9 and 10 to fix this issue.
Potential Impact
The vulnerability allows an attacker to cause a denial of service by crashing Perl processes that use XML::LibXML to parse XML node names containing truncated UTF-8 sequences. There is no indication of confidentiality or integrity impact. No known exploits are reported in the wild at this time.
Mitigation Recommendations
Red Hat has released updated packages for perl-XML-LibXML that fix this vulnerability. Users should apply the security updates provided for Red Hat Enterprise Linux 9 and 10 as detailed in Red Hat advisories RHSA-2026:39553 and RHSA-2026:39547. Patch details and update instructions are available at https://access.redhat.com/articles/11258. Applying these official fixes fully mitigates the issue.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:39553
- Cve Count
- 1
- Additional Cves
- []
- Cvss Version
- null
Threat ID: 6a577ef368715ace43b415c4
Added to database: 07/15/2026, 12:37:07 UTC
Last enriched: 08/24/2026, 15:23:28 UTC
Last updated: 08/27/2026, 08:44:41 UTC
Views: 59
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.