[ALSA-2026:7680] Important: perl-XML-Parser security update
Type:
security
Severity:
important
Release date:
2026-04-15
Description:
This module provides ways to parse XML documents. It is built on top of XML::Parser::Expat, which is a lower level interface to James Clark's expat library. Each call to one of the parsing methods creates a new instance of XML::Parser::Expat which is then used to parse the document. Expat options may be provided when the XML::Parser object is created. These options are then passed on to the Expat object on each parse call. They can also be given as extra arguments to the parse methods, in which case they override options given at XML::Parser creation time. Security Fix(es): * perl-xml-parser: XML::Parser: Memory corruption via deeply nested XML files (CVE-2006-10003) * perl-xml-parser: XML::Parser for Perl: Heap corruption and denial of service from crafted XML input (CVE-2006-10002) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 perl-XML-Parser-2.47-6.1.el10_1.aarch64.rpm cd9792480ac39c65febad007691832fca7127b597ca81e620f78ebd6bcc8eebb
ppc64le perl-XML-Parser-2.47-6.1.el10_1.ppc64le.rpm 2863a1cd07c2661d468a1b4170afb6835c8adfb6d24e80115d95040e2d867259
s390x perl-XML-Parser-2.47-6.1.el10_1.s390x.rpm 06657bbbb07cceb8f37bf756dac558642a243349401580773549dedd3c22bc16
x86_64 perl-XML-Parser-2.47-6.1.el10_1.x86_64.rpm ccb5dc056d290d3683093b1170c3ccd274f01074d23d53d063a4f08ad418c864
x86_64_v2 perl-XML-Parser-2.47-6.1.el10_1.x86_64_v2.rpm 25bab2a85f1881b48a89a88ec07ce02b1c4b0739317c752181da04f388585ddb
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.