- What: Security update for perl-XML-Parser in Red Hat Enterprise Linux
- Impact: Systems using Red Hat Enterprise Linux 9.4 Extended Update Support
Red Hat Product Errata RHSA-2026:9259 - Security Advisory Issued: 2026-04-21 Updated: 2026-04-21 RHSA-2026:9259 - Security Advisory Overview Updated Packages Synopsis Important: perl-XML-Parser security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for perl-XML-Parser is now available for Red Hat Enterprise Linux 9.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description This module provides ways to parse XML documents. It is built on top of XML::Parser::Expat, which is a lower level interface to James Clark's expat library. Each call to one of the parsing methods creates a new instance of XML::Parser::Expat which is then used to parse the document. Expat options may be provided when the XML::Parser object is created. These options are then passed on to the Expat object on each parse call. They can also be given as extra arguments to the parse methods, in which case they override options given at XML::Parser creation time. Security Fix(es): perl-xml-parser: XML::Parser: Memory corruption via deeply nested XML files (CVE-2006-10003) perl-xml-parser: XML::Parser for Perl: Heap corruption and denial of service from crafted XML input (CVE-2006-10002) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.4 x86_64 Red Hat Enterprise Linux Server - AUS 9.4 x86_64 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.4 s390x Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.4 ppc64le Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.4 aarch64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.4 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4 x86_64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.4 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.4 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.4 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.4 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.4 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.4 s390x Fixes BZ - 2448999 - CVE-2006-10003 perl-xml-parser: XML::Parser: Memory corruption via deeply nested XML files BZ - 2449001 - CVE-2006-10002 perl-xml-parser: XML::Parser for Perl: Heap corruption and denial of service from crafted XML input CVEs CVE-2006-10002 CVE-2006-10003 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.4 SRPM perl-XML-Parser-2.46-9.el9_4.1.src.rpm SHA-256: 8f8bc6acc993ccd465668d98d1293f749d99428764895c15ce410d7c0fb74ff3 x86_64 perl-XML-Parser-2.46-9.el9_4.1.x86_64.rpm SHA-256: cb255fe3f93fa0996cd76d3ddbeb1ed582e361460a91f4ca8491c618e4ff00dc perl-XML-Parser-debuginfo-2.46-9.el9_4.1.x86_64.rpm SHA-256: 6e6c05b16a5c1b2d679ca649aa39fdca9f77eabe2f07c710b9a2a9bafff9006b perl-XML-Parser-debugsource-2.46-9.el9_4.1.x86_64.rpm SHA-256: 46f1b76d1cf1d9e4df731d293d3ca8434356a8b4a06104c190296632b33e0b39 Red Hat Enterprise Linux Server - AUS 9.4 SRPM perl-XML-Parser-2.46-9.el9_4.1.src.rpm SHA-256: 8f8bc6acc993ccd465668d98d1293f749d99428764895c15ce410d7c0fb74ff3 x86_64 perl-XML-Parser-2.46-9.el9_4.1.x86_64.rpm SHA-256: cb255fe3f93fa0996cd76d3ddbeb1ed582e361460a91f4ca8491c618e4ff00dc perl-XML-Parser-debuginfo-2.46-9.el9_4.1.x86_64.rpm SHA-256: 6e6c05b16a5c1b2d679ca649aa39fdca9f77eabe2f07c710b9a2a9bafff9006b perl-XML-Parser-debugsource-2.46-9.el9_4.1.x86_64.rpm SHA-256: 46f1b76d1cf1d9e4df731d293d3ca8434356a8b4a06104c190296632b33e0b39 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.4 SRPM perl-XML-Parser-2.46-9.el9_4.1.src.rpm SHA-256: 8f8bc6acc993ccd465668d98d1293f749d99428764895c15ce410d7c0fb74ff3 s390x perl-XML-Parser-2.46-9.el9_4.1.s390x.rpm SHA-256: 1a2899101efd9d24e00f1a0182a146d0eee9a1b7a16c2ff1b1d3cc3bf6d0130e perl-XML-Parser-debuginfo-2.46-9.el9_4.1.s390x.rpm SHA-256: ba8e840dc9c330aaaf4c8a371d6e295ff1958221c01490ee42b4fcfe915fe3ba perl-XML-Parser-debugsource-2.46-9.el9_4.1.s390x.rpm SHA-256: 9e4248b617676416a2c462e272df04c4c37f3d9046e0d6623b245de25cc2b474 Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.4 SRPM perl-XML-Parser-2.46-9.el9_4.1.src.rpm SHA-256: 8f8bc6acc993ccd465668d98d1293f749d99428764895c15ce410d7c0fb74ff3 ppc64le perl-XML-Parser-2.46-9.el9_4.1.ppc64le.rpm SHA-256: 39085e6b6bf01695aba85d9deb21702c74731aeac5f0e545a23063e5e52ad452 perl-XML-Parser-debuginfo-2.46-9.el9_4.1.ppc64le.rpm SHA-256: 3c23e465d600fb301be12097af95ef47bae09a1ca36c89269719597a1e09e0ab perl-XML-Parser-debugsource-2.46-9.el9_4.1.ppc64le.rpm SHA-256: 8191b6033c7da72d909a5ee2408d45e1f1fd495cefecd55c1251c2fa431972a0 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.4 SRPM perl-XML-Parser-2.46-9.el9_4.1.src.rpm SHA-256: 8f8bc6acc993ccd465668d98d1293f749d99428764895c15ce410d7c0fb74ff3 aarch64 perl-XML-Parser-2.46-9.el9_4.1.aarch64.rpm SHA-256: c34a1d1634cd02b0df41f624b8690c5fdbb76d242e57ea9651c74c6a630e2665 perl-XML-Parser-debuginfo-2.46-9.el9_4.1.aarch64.rpm SHA-256: e04544fab8ba8a6c62bd996ded7e52a150749355964a040f9fdc41daac375a71 perl-XML-Parser-debugsource-2.46-9.el9_4.1.aarch64.rpm SHA-256: 41cc240e9f1bc7805ef31e76e12208373ad0a7b5088ca53044ad532f9c501939 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.4 SRPM perl-XML-Parser-2.46-9.el9_4.1.src.rpm SHA-256: 8f8bc6acc993ccd465668d98d1293f749d99428764895c15ce410d7c0fb74ff3 ppc64le perl-XML-Parser-2.46-9.el9_4.1.ppc64le.rpm SHA-256: 39085e6b6bf01695aba85d9deb21702c74731aeac5f0e545a23063e5e52ad452 perl-XML-Parser-debuginfo-2.46-9.el9_4.1.ppc64le.rpm SHA-256: 3c23e465d600fb301be12097af95ef47bae09a1ca36c89269719597a1e09e0ab perl-XML-Parser-debugsource-2.46-9.el9_4.1.ppc64le.rpm SHA-256: 8191b6033c7da72d909a5ee2408d45e1f1fd495cefecd55c1251c2fa431972a0 Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4 SRPM perl-XML-Parser-2.46-9.el9_4.1.src.rpm SHA-256: 8f8bc6acc993ccd465668d98d1293f749d99428764895c15ce410d7c0fb74ff3 x86_64 perl-XML-Parser-2.46-9.el9_4.1.x86_64.rpm SHA-256: cb255fe3f93fa0996cd76d3ddbeb1ed582e361460a91f4ca8491c618e4ff00dc perl-XML-Parser-debuginfo-2.46-9.el9_4.1.x86_64.rpm SHA-256: 6e6c05b16a5c1b2d679ca649aa39fdca9f77eabe2f07c710b9a2a9bafff9006b perl-XML-Parser-debugsource-2.46-9.el9_4.1.x86_64.rpm SHA-256: 46f1b76d1cf1d9e4df731d293d3ca8434356a8b4a06104c190296632b33e0b39 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.4 SRPM perl-XML-Parser-2.46-9.el9_4.1.src.rpm SHA-256: 8f8bc6acc993ccd465668d98d1293f749d99428764895c15ce410d7c0fb74ff3 aarch64 perl-XML-Parser-2.46-9.el9_4.1.aarch64.rpm SHA-256: c34a1d1634cd02b0df41f624b8690c5fdbb76d242e57ea9651c74c6a630e2665 perl-XML-Parser-debuginfo-2.46-9.el9_4.1.aarch64.rpm SHA-256: e04544fab8ba8a6c62bd996ded7e52a150749355964a040f9fdc41daac375a71 perl-XML-Parser-debugsource-2.46-9.el9_4.1.aarch64.rpm SHA-256: 41cc240e9f1bc7805ef31e76e12208373ad0a7b5088ca53044ad532f9c501939 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.4 SRPM perl-XML-Parser-2.46-9.el9_4.1.src.rpm SHA-256: 8f8bc6acc993ccd465668d98d1293f749d99428764895c15ce410d7c0fb74ff3 s390x perl-XML-Parser-2.46-9.el9_4.1.s390x.rpm SHA-256: 1a2899101efd9d24e00f1a0182a146d0eee9a1b7a16c2ff1b1d3cc3bf6d0130e perl-XML-Parser-debuginfo-2.46-9.el9_4.1.s390x.rpm SHA-256: ba8e840dc9c330aaaf4c8a371d6e295ff1958221c01490ee42b4fcfe915fe3ba perl-XML-Parser-debugsource-2.46-9.el9_4.1.s390x.rpm SHA-256: 9e4248b617676416a2c462e272df04c4c37f3d9046e0d6623b245de25cc2b474 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.4 SRPM perl-XML-Parser-2.46-9.el9_4.1.src.rpm SHA-256: 8f8bc6acc993ccd465668d98d1293f749d99428764895c15ce410d7c0fb74ff3 x86_64 perl-XML-Parser-2.46-9.el9_4.1.x86_64.rpm SHA-256: cb255fe3f93fa0996cd76d3ddbeb1ed582e361460a91f4ca8491c618e4ff00dc perl-XML-Parser-debuginfo-2.46-9.el9_4.1.x86_64.rpm SHA-256: 6e6c05b16a5c1b2d679ca649aa39fdca9f77eabe2f07c710b9a2a9bafff9006b perl-XML-Parser-debugsource-2.46-9.el9_4.1.x86_64.rpm SHA-256: 46f1b76d1cf1d9e4df731d293d3ca8434356a8b4a06104c190296632b33e0b39 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.4 SRPM perl-XML-Parser-2.46-9.el9_4.1.src.rpm SHA-256: 8f8bc6acc993ccd465668d98d1293f749d99428764895c15ce410d7c0fb74ff3 aarch64 perl-XML-Parser-2.46-9.el9_4.1.aarch64.rpm SHA-256: c34a1d1634cd02b0df41f624b8690c5fdbb76d242e57ea9651c74c6a630e2665 perl-XML-Parser-debuginfo-2.46-9.el9_4.1.aarch64.rpm SHA-256: e04544fab8ba8a6c62bd996ded7e52a150749355964a040f9fdc41daac375a71 perl-XML-Parser-debugsource-2.46-9.el9_4.1.aarch64.rpm SHA-256: 41cc240e9f1bc7805ef31e76e12208373ad0a7b5088ca53044ad532f9c501939 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.4 SRPM perl-XML-Parser-2.46-9.el9_4.1.src.rpm SHA-256: 8f8bc6acc993ccd465668d98d1293f749d99428764895c15ce410d7c0fb74ff3 ppc64le perl-XML-Parser-2.46-9.el9_4.1.ppc64le.rpm SHA-256: 39085e6b6bf01695aba85d9deb21702c74731aeac5f0e545a23063e5e52ad452 perl-XML-Parser-debuginfo-2.46-9.el9_4.1.ppc64le.rpm SHA-256: 3c23e465d600fb301be12097af95ef47bae09a1ca36c89269719597a1e09e0ab per