XML::Parser versions through 2.47 for Perl has an off-by-one heap buffer overflow in st_serial_stack. In the case (stackptr == stacksize - 1), the stack will NOT be expanded. Then the new value will be written at location (++stackptr), which equals stacksize and therefore falls just outside the allocated buffer. The bug can be observed when parsing an XML file with very deep element nesting
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:7680 https://access.redhat.com/errata/RHSA-2026:7680
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:7681 https://access.redhat.com/errata/RHSA-2026:7681
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:7679 https://access.redhat.com/errata/RHSA-2026:7679
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:8577 https://access.redhat.com/errata/RHSA-2026:8577
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2026:8578 https://access.redhat.com/errata/RHSA-2026:8578
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Advanced Update Support Via RHSA-2026:8609 https://access.redhat.com/errata/RHSA-2026:8609
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:8608 https://access.redhat.com/errata/RHSA-2026:8608
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2026:8610 https://access.redhat.com/errata/RHSA-2026:8610
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:9110 https://access.redhat.com/errata/RHSA-2026:9110
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2026:9246 https://access.redhat.com/errata/RHSA-2026:9246
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:9258 https://access.redhat.com/errata/RHSA-2026:9258
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2026:9259 https://access.redhat.com/errata/RHSA-2026:9259
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:9605 https://access.redhat.com/errata/RHSA-2026:9605