XML::Parser versions through 2.47 for Perl could overflow the pre-allocated buffer size cause a heap corruption (double free or corruption) and crashes. A :utf8 PerlIO layer, parse_stream() in Expat.xs could overflow the XML input buffer because Perl's read() returns decoded characters while SvPV() gives back multi-byte UTF-8 bytes that can exceed the pre-allocated buffer size. This can cause heap corruption (double free or corruption) and crashes.
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:7680 https://access.redhat.com/errata/RHSA-2026:7680
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:7681 https://access.redhat.com/errata/RHSA-2026:7681
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:7679 https://access.redhat.com/errata/RHSA-2026:7679
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:8577 https://access.redhat.com/errata/RHSA-2026:8577
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2026:8578 https://access.redhat.com/errata/RHSA-2026:8578
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Advanced Update Support Via RHSA-2026:8609 https://access.redhat.com/errata/RHSA-2026:8609
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:8608 https://access.redhat.com/errata/RHSA-2026:8608
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2026:8610 https://access.redhat.com/errata/RHSA-2026:8610
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:9110 https://access.redhat.com/errata/RHSA-2026:9110
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2026:9246 https://access.redhat.com/errata/RHSA-2026:9246
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:9258 https://access.redhat.com/errata/RHSA-2026:9258
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2026:9259 https://access.redhat.com/errata/RHSA-2026:9259
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:9605 https://access.redhat.com/errata/RHSA-2026:9605