[ALSA-2026:7679] Important: perl-XML-Parser security update
Type:
security
Severity:
important
Release date:
2026-04-15
Description:
This module provides ways to parse XML documents. It is built on top of XML::Parser::Expat, which is a lower level interface to James Clark's expat library. Each call to one of the parsing methods creates a new instance of XML::Parser::Expat which is then used to parse the document. Expat options may be provided when the XML::Parser object is created. These options are then passed on to the Expat object on each parse call. They can also be given as extra arguments to the parse methods, in which case they override options given at XML::Parser creation time. Security Fix(es): * perl-xml-parser: XML::Parser: Memory corruption via deeply nested XML files (CVE-2006-10003) * perl-xml-parser: XML::Parser for Perl: Heap corruption and denial of service from crafted XML input (CVE-2006-10002) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 perl-XML-Parser-2.46-9.1.el9_7.aarch64.rpm d38c25576d9923695f67f5ff67a4e41521d74f7e05b70cb9f6641eb83cde6c54
ppc64le perl-XML-Parser-2.46-9.1.el9_7.ppc64le.rpm c0c35931aa30737e018f9ffa8b2d27f85bb0c6f1177e177c01a38dfd2b885f5f
s390x perl-XML-Parser-2.46-9.1.el9_7.s390x.rpm 9de859369abe06c25674a138c34f9c27f9c18a734133f26895bec4077edd2867
x86_64 perl-XML-Parser-2.46-9.1.el9_7.x86_64.rpm f8e9abf55ad49e9c443053eba8ff353b23c0dd40a3e5fcdbefbabf6e9dfc4926
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.