[DSA 6428-1] libyaml-syck-perl security update

Salvatore Bonaccorso <[email protected]>
Newsgroups gmane.linux.debian.user.security.announce
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-6428-1                   [email protected]
https://www.debian.org/security/                     Salvatore Bonaccorso
August 10, 2026                       https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : libyaml-syck-perl
CVE ID         : CVE-2026-5089 CVE-2026-13713 CVE-2026-57075 CVE-2026-57076
                 CVE-2026-57077
Debian Bug     : 1142267

Several vulnerabilities were discovered in libyaml-syck-perl, a Perl
module providing a fast, lightweight YAML loader and dumper, which could
result in denial of service and potentially arbitrary code execution.

For the stable distribution (trixie), these problems have been fixed in
version 1.34-2+deb13u3.

We recommend that you upgrade your libyaml-syck-perl packages.

For the detailed security status of libyaml-syck-perl please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/libyaml-syck-perl

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: [email protected]
-----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmp6INZfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND
z0QeSRAAkdCQEallM+91QTwJZdUeOYFBNMoYkFrpGjL+RlFX7jynxc/5ayMJE3w7
SFiaE8/WsdnXQu3KE6pRVLpqRfYluWSgOlNlT5y91RYDxkeHqS/uKgTqN+0c6Izw
tDbI24z9wz/jxgJOndaQSMC0sn0vVFrzW+57w9C4YoeFBuTvmKgTBkVJAdEd1NJx
bEaa442GSRCG2imW1AU1y76Jo3+OxFWmyytycJs38wWItHVrUruuvzCQ26Ok0IEt
4SY3V6QVNujqZ49AgNKhGXGJqh3RFYUmd/5Gr861NtblmeSXfkJV8S2clWDpMDlO
8fzW7juq/aHEdYPwk0mS/pMrTIn7NIWBYCJkR80i/aqD7Evof+VY48a8+3w8kySX
KH0YUkheEG0iBv6pgrAHzsW3vQJ6j+OpVtNv3sX0PaQew7Bd8v0csKhwsSfft6aq
XFzqXrd0dUeqO7V8rW4YtjGCsVxKgCzd7diyiRZA6YhxmnevA7IvvcyFzJTY7vD9
FzbPEXVxSllBPFSJNVB6ZGxepVCqu5h6eGzZ9QYx8W9k5qy36pdHeH50/sTdebBm
Ndm4dFuzClJ1QjCaOv5QUT35Ehz2v/Btsgb8eqidzAUfePXZE9HMWBMtVA2Hk7Aj
lX/pa1o5SVkCCaNh4oV2OhYnDthwyBDU/FI9LAej982NjsTocqk=
=l3lN
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.