Updated perl-YAML-Syck packages fix security vulnerabilities
Publication date: 02 Sep 2026Modification date: 02 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-13713 , CVE-2026-57075 , CVE-2026-57076 , CVE-2026-57077
Description
YAML::Syck versions before 1.47 for Perl allow a use-after-free and
double-free via an anchor node freed while still on the parser value
stack
YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via
a signed-char lookup-table index in syck_base64dec
YAML::Syck versions before 1.47 for Perl allow a heap use-after-free via
an anchor name reused as an anchors-table key in syck_hdlr_add_anchor
YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via
an unbounded newline scan in newline_len
References
- https://bugs.mageia.org/show_bug.cgi?id=35949
- https://www.openwall.com/lists/oss-security/2026/07/17/1
- https://www.openwall.com/lists/oss-security/2026/07/17/2
- https://www.openwall.com/lists/oss-security/2026/07/17/3
- https://www.openwall.com/lists/oss-security/2026/07/17/4
- https://metacpan.org/release/TODDR/YAML-Syck-1.47/changes
- https://www.cve.org/CVERecord?id=CVE-2026-13713
- https://www.cve.org/CVERecord?id=CVE-2026-57075
- https://www.cve.org/CVERecord?id=CVE-2026-57076
- https://www.cve.org/CVERecord?id=CVE-2026-57077
SRPMS
10/core
- perl-YAML-Syck-1.470.0-1.mga10
9/core
- perl-YAML-Syck-1.470.0-1.mga9