Updated perl-JavaScript-Minifier-XS package fixes security vulnerabilities
Publication date: 20 Jul 2026Modification date: 20 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-56017 , CVE-2026-56018
Description
The updated package fixes security vulnerabilities:
JavaScript::Minifier::XS versions before 0.16 for Perl crash with a NULL
pointer dereference when the first meaningful token of the input is a
slash. (CVE-2026-56017)
JavaScript::Minifier::XS versions before 0.16 for Perl leak memory on
every call to minify(), allowing unbounded memory growth.
(CVE-2026-56018)
References
- https://bugs.mageia.org/show_bug.cgi?id=35780
- https://www.openwall.com/lists/oss-security/2026/06/29/16
- https://www.openwall.com/lists/oss-security/2026/06/29/17
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/JRQ3MRFSD4VDM6LUSDFWM5CGXIVDZXIV/
- https://www.cve.org/CVERecord?id=CVE-2026-56017
- https://www.cve.org/CVERecord?id=CVE-2026-56018
SRPMS
10/core
- perl-JavaScript-Minifier-XS-0.160.0-1.mga10
9/core
- perl-JavaScript-Minifier-XS-0.160.0-1.mga9