{"id":"openSUSE-SU-2026:20771-1","summary":"Security update for perl-YAML-Syck","details":"This update for perl-YAML-Syck fixes the following issues:\n\nChanges in perl-YAML-Syck:\n\n- updated to 1.450.0 (1.45)\n    [Bug Fixes]\n    - Fix: use syck_base64_free() to fix Windows \"Free to wrong pool\" crash\n      in base64 encode/decode buffers; also plugs a memory leak (PR #189)\n    - Fix: clear type tag on blessed scalar alias early-return so the stale\n      tag no longer leaks onto the next emitted item (GH #193, PR #194)\n    - Fix: negative float#base60 values produce wrong results; strip sign\n      before accumulating and avoid negative zero for portable\n      stringification (PR #191)\n    - Fix: prevent memory leaks when Load/LoadJSON croak on parse errors\n      (PR #192)\n    [Maintenance]\n    - Test: add coverage for SortKeys and JSON MaxDepth (PR #188)\n    - Test: add error handling coverage for LoadFile/DumpFile (PR #190)\n    - Update README\n\n- updated to 1.440.0 (1.44)\n    [Bug Fixes]\n    - Fix: positive hex and octal values parsed as 0 with ImplicitTyping\n      (PR #187)\n    - Fix: resolve uintptr_t redefinition error on Win64 MinGW\n      (PR #186)\n  1.43 Apr 01 2026\n    [Bug Fixes]\n    - Fix: prevent resource leaks on croak/early-return paths in Dump\n      (PR #161)\n    - Fix: prevent output SV leaks on croak in Dump/DumpFile callers\n      (PR #163)\n    - Fix: Load() in list context returns empty list for empty/undef input;\n      also applies to LoadBytes and LoadUTF8 (GH #164, PR #165)\n    - Fix: DumpCode serializes prototype string instead of code body\n      (PR #168)\n    - Fix: memory leak in !perl/scalar Load — newRV_inc should be\n      newRV_noinc (PR #170)\n    - Fix: add pTHX_ to SAVEDESTRUCTOR_X callback for threaded Perl\n      (GH #175, PR #176)\n    - Fix: add TODO guard for eval_pv leak on Perl \u003c 5.14\n      (GH #179, PR #180)\n    - Fix: negative hex and octal values parsed as 0 with ImplicitTyping\n      (PR #183)\n    - Fix: negative int#base60 values produce unsigned wraparound (PR #185)\n    [Improvements]\n    - Modernize META_MERGE for CPANTS compliance (PR #162)\n    - Fix hash table size handling and remove compile warnings in syck_st\n      (PR #174)\n    [Maintenance]\n    - Restore TODO guard for Dump code leak test on Perl \u003c 5.26 (PR #167)\n    - Resolve 2010 TODO in perl_json_postprocess with test coverage\n      (PR #166)\n    - CI: upgrade actions to resolve Node.js 20 deprecation warnings\n      (PR #177)\n  1.42 Mar 27 2026\n    [Bug Fixes]\n    - Fix: replace strtok() with strpbrk() and fix sign-compare warnings in\n      perl_syck.h (PR #145)\n    - Fix: terminate plain scalars at document boundaries --- and ... (PR #150)\n    - Fix: skip %TAG and %YAML directives in document header (PR #151)\n    - Fix: plug SV leak when eval_pv croaks on bad perl/code blocks (PR #153)\n    - Fix: allow non-specific tag '!' before block scalars (GH #27, PR #102)\n    - Fix: remove spurious %type \u003cnodeId\u003e for indent_open in gram.y\n      (GH #157, PR #158)\n    - Fix: use modern bison %define api.prefix directive (GH #159, PR #160)\n    [Improvements]\n    - Implement YAML merge key (\u003c\u003c) support (PR #149)\n    [Maintenance]\n    - Remove dead Perl 5.6/5.8 version guards from test files (PR #146)\n    - Add YAML 1.0 spec compliance audit and coverage tests (PR #148)\n    - Add comprehensive round-trip tests for YAML 1.0 spec features (PR #152)\n    - Remove unneeded TODO in t/json-basic.t (PR #154)\n    - Add regex Dump/Load/round-trip tests to perl tag scheme (PR #155)\n    - Do not require a .y file to build YAML::Syck; add brew support for bison\n    - Don't ship docs/ directory in tarball\n  1.41 Mar 22 2026\n    [Bug Fixes]\n    - Fix float parsing on -Dusequadmath perls: use Perl's Atof() instead of\n      strtod() so that floats like -3.14 are not corrupted by double-precision\n      rounding artifacts (GH #140, PR #141)\n  1.39 Mar 21 2026\n    [Bug Fixes]\n    - Fix t/yaml-implicit-typing.t failure with -Duselongdouble perls (GH #138, PR #139)\n  1.38 Mar 20 2026\n    [Bug Fixes]\n    - Fix: escape solidus (/) as \\/ in JSON::Syck::Dump for XSS safety (GH #125, PR #130)\n    - Fix: anchor tracking for blessed scalar refs in Dump (GH #126, PR #131)\n    - Fix: prevent buffer underflow in base60 (sexagesimal) parsing (PR #133)\n    - Fix: guard against NULL type from strtok in tag parsing (PR #135)\n    - Fix: correct copy-paste bug in syck_seq_assign() ASSERT macros (PR #137)\n    [Improvements]\n    - Resolve TODO tests for empty/invalid YAML to match actual behavior (GH #127, PR #129)\n    [Maintenance]\n    - Remove dead Perl 5.6 TODOs and convert 5.8 TODO to SKIP (PR #129)\n    - Add comprehensive implicit type resolution test suite (PR #137)\n    - Update MANIFEST to include all unit tests\n    - Clean up test names to remove unnecessary numbering\n  1.37 Mar 18 2026\n    [Features]\n    - Add LoadBytes, LoadUTF8, DumpBytes, DumpUTF8 functions (GH #51)\n    [Fixes]\n    - Fix heap buffer overflow in the YAML emitter - CVE-2026-4177 (GH #67)\n      bsc#1259757\n    - Fix DumpFile with tied filehandles (IO::String, IO::Scalar) (GH #22)\n    - Fix _is_glob to recognize IO::Handle subclasses (GH #23)\n    - Fix memory leak when dumping filehandles (RT#41199, GH #42)\n    - Fix dumping of tied hashes (GH #31)\n    - Fix dumping strings starting with '...' as unquoted plain scalars (GH #34)\n    - Fix dumping strings with tabs and carriage returns as plain scalars (GH #59)\n    - Fix double-dash YAML parsing (RT#34073, GH #35)\n    - Fix extra newline after empty arrays/hashes in YAML output (GH #36)\n    - Remove trailing whitespace from YAML output lines (GH #37, #38, #39)\n    - Fix quoting of \\r and \\t in YAML output instead of emitting raw bytes (GH #40)\n    - Fix growing !!perl/regexp objects in roundtrips (GH #43)\n    - Fix quoted '=' being transformed into 'str' (GH #45)\n    - Fix backslash-space escape in double-quoted YAML strings (GH #61)\n    - Fix flow sequence comma separator not recognized without trailing space (GH #60)\n    - Fix wide character warning in DumpFile (GH #28)\n    - Fix inline arrays without space after comma (GH #25)\n    - Fix: quote strings matching YAML implicit types to prevent roundtrip failures (GH #26)\n    - Fix JSON::Syck::Dump to use JSON-valid \\uXXXX escapes in output (GH #21)\n    - Fix JSON::Syck::Load decoding of \\/ and \\uXXXX escape sequences (GH #30)\n    - Fix: apply JSON postprocessing to JSON::Syck::DumpFile output (GH #104)\n    - Fix: add tied-filehandle fallback to JSON::Syck::DumpFile (GH #98)\n    - Fix: handle JSON escape sequences in SingleQuote mode Load (GH #99)\n    - Fix: restore Perl 5.8 compatibility in test suite (GH #121)\n    - Fix: correct copy-paste error in Makefile.PL clean target (GH #101)\n    - Fix: correct $SortKeys POD default from false to true (GH #100)\n    - Fix: correct POD documentation errors (GH #103)\n    [Maintenance]\n    - Add C23-compatible function prototypes for GCC 15 compatibility (GH #112)\n    - Silence macOS compiler warnings (GH #92)\n    - Guard stdint.h include for portability (HP-UX 11.11) (GH #33)\n    - Guard stdint.h include in syck_st.h for portability (GH #24)\n    - Update ppport.h to 3.68\n    - Add regression tests for magical variable dumping (GH #32)\n    - CI: modernize GitHub Actions workflow (GH #123, #124)\n    - CI: add disttest job to validate MANIFEST completeness\n\n- updated to 1.360.0 (1.36)\n  1.36 Oct 10 2025\n  - Address memory corruption leading to 'str' value being set on empty keys\n    Thanks @timlegge\n    CVE-2025-11683 bsc#1252111\n  1.35 Oct 9 2025\n  - Address parsing error related to string detection on read for empty strings.\n","modified":"2026-05-22T18:24:21.220070262Z","published":"2026-05-19T14:01:13Z","related":["CVE-2025-11683","CVE-2026-4177"],"upstream":["CVE-2025-11683","CVE-2026-4177"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1252111"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259757"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-11683"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4177"}],"schema_version":"1.7.5"}