Red Hat Product Errata RHSA-2026:39878 - Security Advisory Issued: 2026-07-15 Updated: 2026-07-15 RHSA-2026:39878 - Security Advisory Overview Updated Packages Synopsis Important: perl-XML-LibXML security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for perl-XML-LibXML is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description This module implements a Perl interface to the GNOME libxml2 library which provides interfaces for parsing and manipulating XML files. This module allows Perl programmers to make use of the highly capable validating XML parser and the high performance DOM implementation. Security Fix(es): perl-XML-LibXML: XML::LibXML: Denial of Service via truncated UTF-8 in XML node names (CVE-2026-8177) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 8 x86_64 Red Hat Enterprise Linux for IBM z Systems 8 s390x Red Hat Enterprise Linux for Power, little endian 8 ppc64le Red Hat Enterprise Linux for ARM 64 8 aarch64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 8.10 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 8.10 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 8.10 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 8.10 s390x Fixes BZ - 2468684 - CVE-2026-8177 perl-XML-LibXML: XML::LibXML: Denial of Service via truncated UTF-8 in XML node names CVEs CVE-2026-8177 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 8 SRPM perl-XML-LibXML-2.0132-3.el8_10.src.rpm SHA-256: 700dabf92c34ecee6c6e309f31b52cb982a17bc710b36ad073a41b405ec98fdd x86_64 perl-XML-LibXML-2.0132-3.el8_10.x86_64.rpm SHA-256: 2cd443602dcf270971549efd1db4229cb58b1498d5c88176c1f95887ecaf5266 perl-XML-LibXML-debuginfo-2.0132-3.el8_10.x86_64.rpm SHA-256: 6e80939a191688663da004876417a54ddf8e40d86cdfb006ffffa551696920e2 perl-XML-LibXML-debugsource-2.0132-3.el8_10.x86_64.rpm SHA-256: 358edbbfe321fe5c7da8e776b10e05513d09a3527f62b603f2ec394cf11cd691 Red Hat Enterprise Linux for IBM z Systems 8 SRPM perl-XML-LibXML-2.0132-3.el8_10.src.rpm SHA-256: 700dabf92c34ecee6c6e309f31b52cb982a17bc710b36ad073a41b405ec98fdd s390x perl-XML-LibXML-2.0132-3.el8_10.s390x.rpm SHA-256: e914ee2f22d448a2ab09a38e8297c7067ee7caf5f20c4f008392ef0792529816 perl-XML-LibXML-debuginfo-2.0132-3.el8_10.s390x.rpm SHA-256: 332dd04f5d06c87319f366faf20bf275a5e676566fb570d5e64a9f8e31326a73 perl-XML-LibXML-debugsource-2.0132-3.el8_10.s390x.rpm SHA-256: 73f9fbd3f6ee196b08b95e0e9db9db2eb49e5952dd89aac54aa77ddea57d0028 Red Hat Enterprise Linux for Power, little endian 8 SRPM perl-XML-LibXML-2.0132-3.el8_10.src.rpm SHA-256: 700dabf92c34ecee6c6e309f31b52cb982a17bc710b36ad073a41b405ec98fdd ppc64le perl-XML-LibXML-2.0132-3.el8_10.ppc64le.rpm SHA-256: 029364d7bd78da60fa8b6e6b13f8abf564c9ead29cd00c21ade2e63e1b05357e perl-XML-LibXML-debuginfo-2.0132-3.el8_10.ppc64le.rpm SHA-256: 16c711028309440892be4e3237d9f7ec4492385d5ceb01443f6744901c48b69a perl-XML-LibXML-debugsource-2.0132-3.el8_10.ppc64le.rpm SHA-256: b4f89a19cfa26155a9f4bd38f41c2c58ea42b268ace0c26dd23b7b7eceef81db Red Hat Enterprise Linux for ARM 64 8 SRPM perl-XML-LibXML-2.0132-3.el8_10.src.rpm SHA-256: 700dabf92c34ecee6c6e309f31b52cb982a17bc710b36ad073a41b405ec98fdd aarch64 perl-XML-LibXML-2.0132-3.el8_10.aarch64.rpm SHA-256: 4c4fa8fe8bc1ceb11ff5681b60e68a72e830bc24bf21086e4d16868f3ee2bcce perl-XML-LibXML-debuginfo-2.0132-3.el8_10.aarch64.rpm SHA-256: bba93578e4d39f0586ae22d0be521b661241a10268ebbd6cb4254dcc382f1338 perl-XML-LibXML-debugsource-2.0132-3.el8_10.aarch64.rpm SHA-256: a9584906bbabd8500d90c1eaaa2750c60400e2cb521dd72552b50cc52abd7ec5 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 8.10 SRPM perl-XML-LibXML-2.0132-3.el8_10.src.rpm SHA-256: 700dabf92c34ecee6c6e309f31b52cb982a17bc710b36ad073a41b405ec98fdd x86_64 perl-XML-LibXML-2.0132-3.el8_10.x86_64.rpm SHA-256: 2cd443602dcf270971549efd1db4229cb58b1498d5c88176c1f95887ecaf5266 perl-XML-LibXML-debuginfo-2.0132-3.el8_10.x86_64.rpm SHA-256: 6e80939a191688663da004876417a54ddf8e40d86cdfb006ffffa551696920e2 perl-XML-LibXML-debugsource-2.0132-3.el8_10.x86_64.rpm SHA-256: 358edbbfe321fe5c7da8e776b10e05513d09a3527f62b603f2ec394cf11cd691 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 8.10 SRPM perl-XML-LibXML-2.0132-3.el8_10.src.rpm SHA-256: 700dabf92c34ecee6c6e309f31b52cb982a17bc710b36ad073a41b405ec98fdd aarch64 perl-XML-LibXML-2.0132-3.el8_10.aarch64.rpm SHA-256: 4c4fa8fe8bc1ceb11ff5681b60e68a72e830bc24bf21086e4d16868f3ee2bcce perl-XML-LibXML-debuginfo-2.0132-3.el8_10.aarch64.rpm SHA-256: bba93578e4d39f0586ae22d0be521b661241a10268ebbd6cb4254dcc382f1338 perl-XML-LibXML-debugsource-2.0132-3.el8_10.aarch64.rpm SHA-256: a9584906bbabd8500d90c1eaaa2750c60400e2cb521dd72552b50cc52abd7ec5 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 8.10 SRPM perl-XML-LibXML-2.0132-3.el8_10.src.rpm SHA-256: 700dabf92c34ecee6c6e309f31b52cb982a17bc710b36ad073a41b405ec98fdd ppc64le perl-XML-LibXML-2.0132-3.el8_10.ppc64le.rpm SHA-256: 029364d7bd78da60fa8b6e6b13f8abf564c9ead29cd00c21ade2e63e1b05357e perl-XML-LibXML-debuginfo-2.0132-3.el8_10.ppc64le.rpm SHA-256: 16c711028309440892be4e3237d9f7ec4492385d5ceb01443f6744901c48b69a perl-XML-LibXML-debugsource-2.0132-3.el8_10.ppc64le.rpm SHA-256: b4f89a19cfa26155a9f4bd38f41c2c58ea42b268ace0c26dd23b7b7eceef81db Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 8.10 SRPM perl-XML-LibXML-2.0132-3.el8_10.src.rpm SHA-256: 700dabf92c34ecee6c6e309f31b52cb982a17bc710b36ad073a41b405ec98fdd s390x perl-XML-LibXML-2.0132-3.el8_10.s390x.rpm SHA-256: e914ee2f22d448a2ab09a38e8297c7067ee7caf5f20c4f008392ef0792529816 perl-XML-LibXML-debuginfo-2.0132-3.el8_10.s390x.rpm SHA-256: 332dd04f5d06c87319f366faf20bf275a5e676566fb570d5e64a9f8e31326a73 perl-XML-LibXML-debugsource-2.0132-3.el8_10.s390x.rpm SHA-256: 73f9fbd3f6ee196b08b95e0e9db9db2eb49e5952dd89aac54aa77ddea57d0028 The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .
A Denial of Service vulnerability (CVE-2026-8177, CVSS 7.5 High) exists in the perl-XML-LibXML module where processing XML files containing truncated UTF-8 characters in node names can cause a crash. The article advises applying the Red Hat update for Enterprise Linux 8, but specific affected and fixed version numbers for the perl-XML-LibXML package are not provided in the text.