openSUSE-SU-2026:0273-1: important: Security update for perl-YAML-Syck

[email protected]
Newsgroups gmane.linux.suse.security.announce
Message-ID <[email protected]>
   openSUSE Security Update: Security update for perl-YAML-Syck
______________________________________________________________________________

Announcement ID:    openSUSE-SU-2026:0273-1
Rating:             important
References:         #1265155 #1271631 #1271632 #1271633 #1271634 
                    
Cross-References:   CVE-2025-11683 CVE-2026-13713 CVE-2026-5089
                    CVE-2026-57075 CVE-2026-57076 CVE-2026-57077
                   
CVSS scores:
                    CVE-2025-11683 (SUSE): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected Products:
                    openSUSE Backports SLE-15-SP7
______________________________________________________________________________

   An update that fixes 6 vulnerabilities is now available.

Description:

   This update for perl-YAML-Syck fixes the following issues:

   - updated to 1.470.0 (1.47) see
     /usr/share/doc/packages/perl-YAML-Syck/Changes 1.47 Jul 13 2026
     [Security]
       - Fix four libsyck memory-safety CVEs reachable from the default
         YAML::Syck::Load() path on untrusted input with no special flags
         (reported by Paul Johnson via CPANSec, PR #213):
         - CVE-2026-57075 (CWE-125): out-of-bounds read in the base64 decoder
   caused by signed-char indexing of the decode table on !!binary input
   boo#1271632
         - CVE-2026-57076 (CWE-416): use-after-free of an anchor key string
   shared between the node and the anchors table boo#1271633
         - CVE-2026-57077 (CWE-125): one-byte out-of-bounds read in the lexer
   newline scan during block-scalar parsing (incomplete-fix follow-on to
   CVE-2025-11683) boo#1271634
         - CVE-2026-13713 (CWE-416/CWE-415): use-after-free / double-free of
   an anchor node on anchor redefinition, a remote-crash DoS from a 7-byte
   input boo#1271631
       - Harden syck_base64dec() to bounds-check each read so it cannot run
         past a non-NUL-terminated input buffer (defense-in-depth for callers
         passing raw buffers; PR #213) [Bug Fixes]
       - Fix: enforce $MaxDepth on Load to prevent C-stack exhaustion from
         deeply nested YAML/JSON input; YAML::Syck and JSON::Syck Load now
         default to 512, matching Dump (PR #204)
       - Fix: emit YAML canonical forms (.nan, .inf, -.inf) for NaN/Inf
         values in Dump so they roundtrip with ImplicitTyping instead of
         reloading as plain strings (PR #201) [Maintenance]
       - CI: add an AddressSanitizer job that builds the XS with
         -fsanitize=address and runs the suite plus the CVE trigger inputs to
   catch libsyck memory-safety defects; de-pin the libasan version so it
   tracks the runner's GCC (PR #213)

   - updated to 1.460.0 (1.46) see
     /usr/share/doc/packages/perl-YAML-Syck/Changes 1.46 May 24 2026 [Bug
     Fixes]
       - Fix: preserve string nature of numeric-looking values in Dump; pure
         strings (POK only, no IOK/NOK) are now quoted to maintain roundtrip
         fidelity (GH #199, PR #200)
       - Fix: accept trailing commas in flow sequences and mappings ([a, b,]
         and {a: 1,}), valid per YAML 1.0/1.1/1.2 spec (GH #195, PR #196)
         [Maintenance]
       - CI: upgrade install-with-cpm to v2 for compatibility with Perl
         versions prior to 5.24 in perldocker containers (GH #197, PR #198)
       - Clean up MANIFEST.SKIP: add #!include_default, remove redundant
         entries, exclude .claude/ from distribution


Patch Instructions:

   To install this openSUSE Security Update use the SUSE recommended installation methods
   like YaST online_update or "zypper patch".

   Alternatively you can run the command listed for your product:

   - openSUSE Backports SLE-15-SP7:

      zypper in -t patch openSUSE-2026-273=1



Package List:

   - openSUSE Backports SLE-15-SP7 (aarch64 i586 ppc64le s390x x86_64):

      perl-YAML-Syck-1.470.0-bp157.2.6.1


References:

   https://www.suse.com/security/cve/CVE-2025-11683.html
   https://www.suse.com/security/cve/CVE-2026-13713.html
   https://www.suse.com/security/cve/CVE-2026-5089.html
   https://www.suse.com/security/cve/CVE-2026-57075.html
   https://www.suse.com/security/cve/CVE-2026-57076.html
   https://www.suse.com/security/cve/CVE-2026-57077.html
   https://bugzilla.suse.com/1265155
   https://bugzilla.suse.com/1271631
   https://bugzilla.suse.com/1271632
   https://bugzilla.suse.com/1271633
   https://bugzilla.suse.com/1271634
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.