CVE-2026-8177: Red Hat Enterprise Linux 10
High severity, CVSS 7.5. EPSS: 0.9% chance of exploitation in the next 30 days.
XML::LibXML versions through 2.0210 for Perl read out-of-bounds heap memory when parsing XML node names containing truncated UTF-8 byte sequences. A node name ending in the middle of a multi byte UTF-8 sequence causes the parser to read past the end of the input string into adjacent heap memory. Any Perl process that passes attacker controlled strings to XML::LibXML's DOM node-name methods can reach this path on the default API. The likely consequence is a crash, causing denial of service.
Affected products
- Red Hat Red Hat Enterprise Linux 10: before 1:2.0210-4.el10_2.1 (fixed in 1:2.0210-4.el10_2.1)
- Red Hat Red Hat Enterprise Linux 10.0 Extended Update Support: before 1:2.0210-4.el10_0.1 (fixed in 1:2.0210-4.el10_0.1)
- Red Hat Red Hat Enterprise Linux 6
- Red Hat Red Hat Enterprise Linux 7
- Red Hat Red Hat Enterprise Linux 8: before 1:2.0132-3.el8_10 (fixed in 1:2.0132-3.el8_10)
- Red Hat Red Hat Enterprise Linux 9: before 1:2.0206-5.el9_8.1 (fixed in 1:2.0206-5.el9_8.1)
- Red Hat Red Hat Enterprise Linux 9.2 Update Services For SAP Solutions: before 1:2.0206-5.el9_2.1 (fixed in 1:2.0206-5.el9_2.1)
- Red Hat Red Hat Enterprise Linux 9.4 Update Services For SAP Solutions: before 1:2.0206-5.el9_4.1 (fixed in 1:2.0206-5.el9_4.1)
- Red Hat Red Hat Enterprise Linux 9.6 Extended Update Support: before 1:2.0206-5.el9_6.1 (fixed in 1:2.0206-5.el9_6.1)
- Red Hat Red Hat Openshift Container Platform 4
- Shlomif Xml::libxml: up to and including 2.0210
Published 2026-05-10. Last modified 2026-09-18.