Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-8177

Опубликовано: 10 мая 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

XML::LibXML versions through 2.0210 for Perl read out-of-bounds heap memory when parsing XML node names containing truncated UTF-8 byte sequences. A node name ending in the middle of a multi byte UTF-8 sequence causes the parser to read past the end of the input string into adjacent heap memory. Any Perl process that passes attacker controlled strings to XML::LibXML's DOM node-name methods can reach this path on the default API. The likely consequence is a crash, causing denial of service.

A flaw was found in XML::LibXML for Perl. A remote attacker could exploit this vulnerability when processing specially crafted XML node names containing incomplete UTF-8 character sequences. This can lead to an out-of-bounds read in heap memory, potentially causing the application to crash and resulting in a denial of service.

Отчет

A flaw was found in perl-XML-LibXML. The XML::LibXML module reads out-of-bounds heap memory when parsing XML node names containing truncated UTF-8 byte sequences. A node name ending in the middle of a multi-byte UTF-8 sequence causes the parser to read past the end of the input string into adjacent heap memory. Any Perl process that passes attacker-controlled strings to XML::LibXML's DOM node-name methods can trigger this flaw, with the likely consequence being a crash causing denial of service. The vulnerability is in the perl-XML-LibXML package specifically, not in the core perl interpreter. In containerised or pod-based deployments, the availability impact may be reduced since crashed processes are typically auto-restarted by the container orchestrator.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6perl-XML-LibXMLOut of support scope
Red Hat Enterprise Linux 7perl-XML-LibXMLAffected
Red Hat OpenShift Container Platform 4rhcosNot affected
Red Hat Enterprise Linux 10perl-XML-LibXMLFixedRHSA-2026:3954714.07.2026
Red Hat Enterprise Linux 8perl-XML-LibXMLFixedRHSA-2026:3987815.07.2026
Red Hat Enterprise Linux 9perl-XML-LibXMLFixedRHSA-2026:3955315.07.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2468684perl-XML-LibXML: XML::LibXML: Denial of Service via truncated UTF-8 in XML node names

EPSS

Процентиль: 46%
0.00629
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

XML::LibXML versions through 2.0210 for Perl read out-of-bounds heap memory when parsing XML node names containing truncated UTF-8 byte sequences. A node name ending in the middle of a multi byte UTF-8 sequence causes the parser to read past the end of the input string into adjacent heap memory. Any Perl process that passes attacker controlled strings to XML::LibXML's DOM node-name methods can reach this path on the default API. The likely consequence is a crash, causing denial of service.

CVSS3: 7.5
nvd
3 месяца назад

XML::LibXML versions through 2.0210 for Perl read out-of-bounds heap memory when parsing XML node names containing truncated UTF-8 byte sequences. A node name ending in the middle of a multi byte UTF-8 sequence causes the parser to read past the end of the input string into adjacent heap memory. Any Perl process that passes attacker controlled strings to XML::LibXML's DOM node-name methods can reach this path on the default API. The likely consequence is a crash, causing denial of service.

CVSS3: 7.5
msrc
3 месяца назад

XML::LibXML versions through 2.0210 for Perl read out-of-bounds heap memory when parsing XML node names containing truncated UTF-8 byte sequences

CVSS3: 7.5
debian
3 месяца назад

XML::LibXML versions through 2.0210 for Perl read out-of-bounds heap m ...

suse-cvrf
около 2 месяцев назад

Security update for perl-XML-LibXML

EPSS

Процентиль: 46%
0.00629
Низкий

7.5 High

CVSS3