Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-6470

Опубликовано: 03 апр. 2026
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2026-6470: perl-YAML-Syck security update (IMPORTANT)

[1.30-6]

  • Resolves: RHEL-156475
  • Fix CVE-2026-4177

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

perl-YAML-Syck

1.30-6.el8_10

Oracle Linux x86_64

perl-YAML-Syck

1.30-6.el8_10

Связанные CVE

Связанные уязвимости

CVSS3: 9.1
ubuntu
22 дня назад

YAML::Syck versions through 1.36 for Perl has several potential security vulnerabilities including a high-severity heap buffer overflow in the YAML emitter. The heap overflow occurs when class names exceed the initial 512-byte allocation. The base64 decoder could read past the buffer end on trailing newlines. strtok mutated n->type_id in place, corrupting shared node data. A memory leak occurred in syck_hdlr_add_anchor when a node already had an anchor. The incoming anchor string 'a' was leaked on early return.

CVSS3: 7.3
redhat
22 дня назад

YAML::Syck versions through 1.36 for Perl has several potential security vulnerabilities including a high-severity heap buffer overflow in the YAML emitter. The heap overflow occurs when class names exceed the initial 512-byte allocation. The base64 decoder could read past the buffer end on trailing newlines. strtok mutated n->type_id in place, corrupting shared node data. A memory leak occurred in syck_hdlr_add_anchor when a node already had an anchor. The incoming anchor string 'a' was leaked on early return.

CVSS3: 9.1
nvd
22 дня назад

YAML::Syck versions through 1.36 for Perl has several potential security vulnerabilities including a high-severity heap buffer overflow in the YAML emitter. The heap overflow occurs when class names exceed the initial 512-byte allocation. The base64 decoder could read past the buffer end on trailing newlines. strtok mutated n->type_id in place, corrupting shared node data. A memory leak occurred in syck_hdlr_add_anchor when a node already had an anchor. The incoming anchor string 'a' was leaked on early return.

CVSS3: 9.1
debian
22 дня назад

YAML::Syck versions through 1.36 for Perl has several potential securi ...

CVSS3: 9.1
github
22 дня назад

YAML::Syck versions through 1.36 for Perl has several potential security vulnerabilities including a high-severity heap buffer overflow in the YAML emitter. The heap overflow occurs when class names exceed the initial 512-byte allocation. The base64 decoder could read past the buffer end on trailing newlines. strtok mutated n->type_id in place, corrupting shared node data. A memory leak occurred in syck_hdlr_add_anchor when a node already had an anchor. The incoming anchor string 'a' was leaked on early return.