openSUSE Security Update: Security update for perl-YAML-Syck
______________________________________________________________________________
Announcement ID: openSUSE-SU-2026:0273-1
Rating: important
References: #1265155 #1271631 #1271632 #1271633 #1271634
Cross-References: CVE-2025-11683 CVE-2026-13713 CVE-2026-5089
CVE-2026-57075 CVE-2026-57076 CVE-2026-57077
CVSS scores:
CVE-2025-11683 (SUSE): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected Products:
openSUSE Backports SLE-15-SP7
______________________________________________________________________________
An update that fixes 6 vulnerabilities is now available.
Description:
This update for perl-YAML-Syck fixes the following issues:
- updated to 1.470.0 (1.47) see
/usr/share/doc/packages/perl-YAML-Syck/Changes 1.47 Jul 13 2026
[Security]
- Fix four libsyck memory-safety CVEs reachable from the default
YAML::Syck::Load() path on untrusted input with no special flags
(reported by Paul Johnson via CPANSec, PR #213):
- CVE-2026-57075 (CWE-125): out-of-bounds read in the base64 decoder
caused by signed-char indexing of the decode table on !!binary input
boo#1271632
- CVE-2026-57076 (CWE-416): use-after-free of an anchor key string
shared between the node and the anchors table boo#1271633
- CVE-2026-57077 (CWE-125): one-byte out-of-bounds read in the lexer
newline scan during block-scalar parsing (incomplete-fix follow-on to
CVE-2025-11683) boo#1271634
- CVE-2026-13713 (CWE-416/CWE-415): use-after-free / double-free of
an anchor node on anchor redefinition, a remote-crash DoS from a 7-byte
input boo#1271631
- Harden syck_base64dec() to bounds-check each read so it cannot run
past a non-NUL-terminated input buffer (defense-in-depth for callers
passing raw buffers; PR #213) [Bug Fixes]
- Fix: enforce $MaxDepth on Load to prevent C-stack exhaustion from
deeply nested YAML/JSON input; YAML::Syck and JSON::Syck Load now
default to 512, matching Dump (PR #204)
- Fix: emit YAML canonical forms (.nan, .inf, -.inf) for NaN/Inf
values in Dump so they roundtrip with ImplicitTyping instead of
reloading as plain strings (PR #201) [Maintenance]
- CI: add an AddressSanitizer job that builds the XS with
-fsanitize=address and runs the suite plus the CVE trigger inputs to
catch libsyck memory-safety defects; de-pin the libasan version so it
tracks the runner's GCC (PR #213)
- updated to 1.460.0 (1.46) see
/usr/share/doc/packages/perl-YAML-Syck/Changes 1.46 May 24 2026 [Bug
Fixes]
- Fix: preserve string nature of numeric-looking values in Dump; pure
strings (POK only, no IOK/NOK) are now quoted to maintain roundtrip
fidelity (GH #199, PR #200)
- Fix: accept trailing commas in flow sequences and mappings ([a, b,]
and {a: 1,}), valid per YAML 1.0/1.1/1.2 spec (GH #195, PR #196)
[Maintenance]
- CI: upgrade install-with-cpm to v2 for compatibility with Perl
versions prior to 5.24 in perldocker containers (GH #197, PR #198)
- Clean up MANIFEST.SKIP: add #!include_default, remove redundant
entries, exclude .claude/ from distribution
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Backports SLE-15-SP7:
zypper in -t patch openSUSE-2026-273=1
Package List:
- openSUSE Backports SLE-15-SP7 (aarch64 i586 ppc64le s390x x86_64):
perl-YAML-Syck-1.470.0-bp157.2.6.1
References:
https://www.suse.com/security/cve/CVE-2025-11683.html
https://www.suse.com/security/cve/CVE-2026-13713.html
https://www.suse.com/security/cve/CVE-2026-5089.html
https://www.suse.com/security/cve/CVE-2026-57075.html
https://www.suse.com/security/cve/CVE-2026-57076.html
https://www.suse.com/security/cve/CVE-2026-57077.html
https://bugzilla.suse.com/1265155
https://bugzilla.suse.com/1271631
https://bugzilla.suse.com/1271632
https://bugzilla.suse.com/1271633
https://bugzilla.suse.com/1271634
lmpx.com only provides a reader for public news (NNTP) servers. It is not
affiliated with the servers or forums shown here and is not responsible for
the content of articles, which is written by their respective authors.