Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-57077

Опубликовано: 16 июл. 2026
Источник: redhat
CVSS3: 4.3

Описание

YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via an unbounded newline scan in newline_len. In the bundled libsyck newline_len and is_newline dereference the scan pointer, and the following byte for a "\r\n" pair, with no NUL-terminator or bounds check. During block-scalar lexing at a document boundary the scan runs one byte past the heap lexer buffer. This is an incomplete fix of CVE-2025-11683, on a lexer path the earlier fix did not cover. Any caller that runs Load or LoadFile on an untrusted document with a block scalar at a document boundary reaches the over-read.

A flaw was found in YAML::Syck. An out-of-bounds read vulnerability exists due to an unbounded newline scan during block-scalar lexing. A remote attacker could exploit this by providing a specially crafted YAML document, leading to potential information disclosure. This issue is an incomplete fix for a previously identified vulnerability.

Отчет

Moderate: An out-of-bounds read flaw in perl-YAML-Syck can lead to information disclosure when processing specially crafted YAML documents. This vulnerability, an incomplete fix for CVE-2025-11683, occurs during block-scalar lexing if an application loads untrusted YAML input containing a block scalar at a document boundary.

Меры по смягчению последствий

To mitigate this vulnerability, restrict applications using perl-YAML-Syck from processing untrusted YAML documents. Ensure that only trusted input sources are parsed by YAML::Syck. If perl-YAML-Syck is not required, consider removing the package to eliminate the exposure, noting that this may affect dependent applications.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6perl-YAML-SyckOut of support scope
Red Hat Enterprise Linux 7perl-YAML-SyckOut of support scope
Red Hat Enterprise Linux 8perl-YAML-SyckFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2501576YAML::Syck: YAML::Syck: Information disclosure via out-of-bounds read

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.7
ubuntu
18 дней назад

YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via an unbounded newline scan in newline_len. In the bundled libsyck newline_len and is_newline dereference the scan pointer, and the following byte for a "\r\n" pair, with no NUL-terminator or bounds check. During block-scalar lexing at a document boundary the scan runs one byte past the heap lexer buffer. This is an incomplete fix of CVE-2025-11683, on a lexer path the earlier fix did not cover. Any caller that runs Load or LoadFile on an untrusted document with a block scalar at a document boundary reaches the over-read.

CVSS3: 7.7
nvd
18 дней назад

YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via an unbounded newline scan in newline_len. In the bundled libsyck newline_len and is_newline dereference the scan pointer, and the following byte for a "\r\n" pair, with no NUL-terminator or bounds check. During block-scalar lexing at a document boundary the scan runs one byte past the heap lexer buffer. This is an incomplete fix of CVE-2025-11683, on a lexer path the earlier fix did not cover. Any caller that runs Load or LoadFile on an untrusted document with a block scalar at a document boundary reaches the over-read.

CVSS3: 7.7
debian
18 дней назад

YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read v ...

CVSS3: 7.7
github
18 дней назад

YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via an unbounded newline scan in newline_len. In the bundled libsyck newline_len and is_newline dereference the scan pointer, and the following byte for a "\r\n" pair, with no NUL-terminator or bounds check. During block-scalar lexing at a document boundary the scan runs one byte past the heap lexer buffer. This is an incomplete fix of CVE-2025-11683, on a lexer path the earlier fix did not cover. Any caller that runs Load or LoadFile on an untrusted document with a block scalar at a document boundary reaches the over-read.

suse-cvrf
6 дней назад

Security update for perl-YAML-Syck

4.3 Medium

CVSS3