Back Linuxsecurity Fedora 43 perl-Cpanel-JSON-XS Critical DoS Fix FEDORA-2026
This update addresses a number of bugs including these security issues: Fix BOM-shift PV-corruption SIGABRT (CVE-2026-9516) Fix dupkeys_as_arrayref type confusion (CVE-2026-9334)
* Thu May 28 2026 Paul Howarth - 4.41-1 - Update to 4.41 - Fix BOM-shift PV-corruption SIGABRT (CVE-2026-9516) - Fix dupkeys_as_arrayref type confusion (CVE-2026-9334) - Fix incr_parse single-quote string delimiter (GH#245) - Fix a one-byte out-of-bounds heap read reachable via allow_barekey on truncated input (GH#244) * Sat Jan 17 2026 Fedora Release Engineering - 4.40-2 - Rebuilt for
* Thu May 28 2026 Paul Howarth - 4.41-1 - Update to 4.41 - Fix BOM-shift PV-corruption SIGABRT (CVE-2026-9516) - Fix dupkeys_as_arrayref type confusion (CVE-2026-9334) - Fix incr_parse single-quote string delimiter (GH#245) - Fix a one-byte out-of-bounds heap read reachable via allow_barekey on truncated input (GH#244) * Sat Jan 17 2026 Fedora Release Engineering - 4.40-2 - Rebuilt for
[ 1 ] Bug #2484331 - CVE-2026-9334 perl-Cpanel-JSON-XS: perl-Cpanel-JSON-XS: Denial of Service via type confusion with duplicate JSON object keys [fedora-all] [ 2 ] Bug #2484333 - CVE-2026-9516 perl-Cpanel-JSON-XS: Cpanel::JSON::XS: Denial of Service via UTF-8 BOM prefixed input [fedora-all]
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-d88c7fac8c' at the command line. For more information, refer to the dnf documentation available at
Get the latest Linux and open source security news straight to your inbox.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
