{"id":"openSUSE-SU-2026:21452-1","summary":"Security update for perl-YAML-Syck","details":"This update for perl-YAML-Syck fixes the following issues:\n\nChanges in perl-YAML-Syck:\n\n- updated to 1.470.0 (1.47)\n    [Security]\n    - Fix four libsyck memory-safety CVEs reachable from the default\n      YAML::Syck::Load() path on untrusted input with no special flags\n      (reported by Paul Johnson via CPANSec, PR #213):\n      - CVE-2026-57075 (CWE-125): out-of-bounds read in the base64 decoder\n        caused by signed-char indexing of the decode table on !!binary input\n        bsc#1271632\n      - CVE-2026-57076 (CWE-416): use-after-free of an anchor key string\n        shared between the node and the anchors table\n        bsc#1271633\n      - CVE-2026-57077 (CWE-125): one-byte out-of-bounds read in the lexer\n        newline scan during block-scalar parsing (incomplete-fix follow-on\n        to CVE-2025-11683)\n        bsc#1271634\n      - CVE-2026-13713 (CWE-416/CWE-415): use-after-free / double-free of an\n        anchor node on anchor redefinition, a remote-crash DoS from a\n        7-byte input\n        bsc#1271631\n    - Harden syck_base64dec() to bounds-check each read so it cannot run past\n      a non-NUL-terminated input buffer (defense-in-depth for callers passing\n      raw buffers; PR #213)\n    [Bug Fixes]\n    - Fix: enforce $MaxDepth on Load to prevent C-stack exhaustion from\n      deeply nested YAML/JSON input; YAML::Syck and JSON::Syck Load now\n      default to 512, matching Dump (PR #204)\n    - Fix: emit YAML canonical forms (.nan, .inf, -.inf) for NaN/Inf values\n      in Dump so they roundtrip with ImplicitTyping instead of reloading as\n      plain strings (PR #201)\n    [Maintenance]\n    - CI: add an AddressSanitizer job that builds the XS with\n      -fsanitize=address and runs the suite plus the CVE trigger inputs to\n      catch libsyck memory-safety defects; de-pin the libasan version so it\n      tracks the runner's GCC (PR #213)\n\n- updated to 1.460.0 (1.46)\n    [Bug Fixes]\n    - Fix: preserve string nature of numeric-looking values in Dump; pure\n      strings (POK only, no IOK/NOK) are now quoted to maintain roundtrip\n      fidelity (GH #199, PR #200)\n    - Fix: accept trailing commas in flow sequences and mappings\n      ([a, b,] and {a: 1,}), valid per YAML 1.0/1.1/1.2 spec\n      (GH #195, PR #196)\n\n    [Maintenance]\n    - CI: upgrade install-with-cpm to v2 for compatibility with Perl\n      versions prior to 5.24 in perldocker containers (GH #197, PR #198)\n    - Clean up MANIFEST.SKIP: add #!include_default, remove redundant\n      entries, exclude .claude/ from distribution\n","modified":"2026-07-31T14:00:25.909911269Z","published":"2026-07-27T08:03:38Z","withdrawn":"2026-07-31T14:00:25.909911121Z","related":["CVE-2025-11683","CVE-2026-13713","CVE-2026-57075","CVE-2026-57076","CVE-2026-57077"],"upstream":["CVE-2025-11683","CVE-2026-13713","CVE-2026-57075","CVE-2026-57076","CVE-2026-57077"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271631"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271632"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271633"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271634"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-11683"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-13713"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-57075"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-57076"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-57077"}],"affected":[{"package":{"name":"perl-YAML-Syck","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/perl-YAML-Syck&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.470.0-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"perl-YAML-Syck":"1.470.0-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21452-1.json"}}],"schema_version":"1.7.5"}