SUSE alert openSUSE-SU-2026:0273-1 (perl-YAML-Syck)
| From: | maintenance@opensuse.org | |
| To: | security-announce@lists.opensuse.org | |
| Subject: | openSUSE-SU-2026:0273-1: important: Security update for perl-YAML-Syck | |
| Date: | Tue, 04 Aug 2026 21:04:45 +0200 | |
| Message-ID: | <20260804190445.7BB2DFDC8@maintenance.suse.de> | |
| Archive-link: | Article |
openSUSE Security Update: Security update for perl-YAML-Syck ______________________________________________________________________________ Announcement ID: openSUSE-SU-2026:0273-1 Rating: important References: #1265155 #1271631 #1271632 #1271633 #1271634 Cross-References: CVE-2025-11683 CVE-2026-13713 CVE-2026-5089 CVE-2026-57075 CVE-2026-57076 CVE-2026-57077 CVSS scores: CVE-2025-11683 (SUSE): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: openSUSE Backports SLE-15-SP7 ______________________________________________________________________________ An update that fixes 6 vulnerabilities is now available. Description: This update for perl-YAML-Syck fixes the following issues: - updated to 1.470.0 (1.47) see /usr/share/doc/packages/perl-YAML-Syck/Changes 1.47 Jul 13 2026 [Security] - Fix four libsyck memory-safety CVEs reachable from the default YAML::Syck::Load() path on untrusted input with no special flags (reported by Paul Johnson via CPANSec, PR #213): - CVE-2026-57075 (CWE-125): out-of-bounds read in the base64 decoder caused by signed-char indexing of the decode table on !!binary input boo#1271632 - CVE-2026-57076 (CWE-416): use-after-free of an anchor key string shared between the node and the anchors table boo#1271633 - CVE-2026-57077 (CWE-125): one-byte out-of-bounds read in the lexer newline scan during block-scalar parsing (incomplete-fix follow-on to CVE-2025-11683) boo#1271634 - CVE-2026-13713 (CWE-416/CWE-415): use-after-free / double-free of an anchor node on anchor redefinition, a remote-crash DoS from a 7-byte input boo#1271631 - Harden syck_base64dec() to bounds-check each read so it cannot run past a non-NUL-terminated input buffer (defense-in-depth for callers passing raw buffers; PR #213) [Bug Fixes] - Fix: enforce $MaxDepth on Load to prevent C-stack exhaustion from deeply nested YAML/JSON input; YAML::Syck and JSON::Syck Load now default to 512, matching Dump (PR #204) - Fix: emit YAML canonical forms (.nan, .inf, -.inf) for NaN/Inf values in Dump so they roundtrip with ImplicitTyping instead of reloading as plain strings (PR #201) [Maintenance] - CI: add an AddressSanitizer job that builds the XS with -fsanitize=address and runs the suite plus the CVE trigger inputs to catch libsyck memory-safety defects; de-pin the libasan version so it tracks the runner's GCC (PR #213) - updated to 1.460.0 (1.46) see /usr/share/doc/packages/perl-YAML-Syck/Changes 1.46 May 24 2026 [Bug Fixes] - Fix: preserve string nature of numeric-looking values in Dump; pure strings (POK only, no IOK/NOK) are now quoted to maintain roundtrip fidelity (GH #199, PR #200) - Fix: accept trailing commas in flow sequences and mappings ([a, b,] and {a: 1,}), valid per YAML 1.0/1.1/1.2 spec (GH #195, PR #196) [Maintenance] - CI: upgrade install-with-cpm to v2 for compatibility with Perl versions prior to 5.24 in perldocker containers (GH #197, PR #198) - Clean up MANIFEST.SKIP: add #!include_default, remove redundant entries, exclude .claude/ from distribution Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP7: zypper in -t patch openSUSE-2026-273=1 Package List: - openSUSE Backports SLE-15-SP7 (aarch64 i586 ppc64le s390x x86_64): perl-YAML-Syck-1.470.0-bp157.2.6.1 References: https://www.suse.com/security/cve/CVE-2025-11683.html https://www.suse.com/security/cve/CVE-2026-13713.html https://www.suse.com/security/cve/CVE-2026-5089.html https://www.suse.com/security/cve/CVE-2026-57075.html https://www.suse.com/security/cve/CVE-2026-57076.html https://www.suse.com/security/cve/CVE-2026-57077.html https://bugzilla.suse.com/1265155 https://bugzilla.suse.com/1271631 https://bugzilla.suse.com/1271632 https://bugzilla.suse.com/1271633 https://bugzilla.suse.com/1271634
