Skip to content
Fedora 44 perl-Cpanel-JSON-XS Moderate Denial of Service CVE-2026

Fedora 44 perl-Cpanel-JSON-XS Moderate Denial of Service CVE-2026

Linuxsecurity LinuxSecurity Advisories June 5, 2026

This update addresses a number of bugs including these security issues: Fix BOM-shift PV-corruption SIGABRT (CVE-2026-9516) Fix dupkeys_as_arrayref type confusion (CVE-2026-9334)

* Thu May 28 2026 Paul Howarth - 4.41-1 - Update to 4.41 - Fix BOM-shift PV-corruption SIGABRT (CVE-2026-9516) - Fix dupkeys_as_arrayref type confusion (CVE-2026-9334) - Fix incr_parse single-quote string delimiter (GH#245) - Fix a one-byte out-of-bounds heap read reachable via allow_barekey on truncated input (GH#244)

* Thu May 28 2026 Paul Howarth - 4.41-1 - Update to 4.41 - Fix BOM-shift PV-corruption SIGABRT (CVE-2026-9516) - Fix dupkeys_as_arrayref type confusion (CVE-2026-9334) - Fix incr_parse single-quote string delimiter (GH#245) - Fix a one-byte out-of-bounds heap read reachable via allow_barekey on truncated input (GH#244)

[ 1 ] Bug #2484331 - CVE-2026-9334 perl-Cpanel-JSON-XS: perl-Cpanel-JSON-XS: Denial of Service via type confusion with duplicate JSON object keys [fedora-all] [ 2 ] Bug #2484333 - CVE-2026-9516 perl-Cpanel-JSON-XS: Cpanel::JSON::XS: Denial of Service via UTF-8 BOM prefixed input [fedora-all]

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-0a82e80353' at the command line. For more information, refer to the dnf documentation available at

Get the latest Linux and open source security news straight to your inbox.

Extracted Entities

Attack Types (1)

Platforms (1)