Critical Memory-Safety Vulnerabilities in Fedora's perl-YAML-Syck Module

Critical Memory-Safety Vulnerabilities in Fedora's perl-YAML-Syck Module

First seen 23 Jul 2026, 12:05 UTC Linuxsecurity 97% similarity 70.5

Article Content

Browse articles
ThreatCluster

Fedora has released an important update for the perl-YAML-Syck module addressing four critical memory-safety CVEs, all of which are reachable from the default YAML::Syck::Load() path on untrusted input. The vulnerabilities include CVE-2026-57075, CVE-2026-57076, CVE-2026-57077, and CVE-2026-13713, all published on 2026-07-16. These vulnerabilities can lead to out-of-bounds reads and use-after-free conditions, potentially resulting in denial-of-service attacks. The affected systems are primarily those running Fedora 43 and 44. The update also includes bug fixes and enhancements to improve the module's overall security posture. Users are advised to apply the update promptly to mitigate risks associated with these vulnerabilities.

Key Points: • Four critical memory-safety CVEs in perl-YAML-Syck affect Fedora 43 and 44. • Vulnerabilities can lead to denial-of-service attacks via untrusted input. • Users must update to the latest version to mitigate these security risks.

ThreatCluster AI

Timeline

2025-10-16
CVE-2025-11683 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-14
Fedora releases update for perl-YAML-Syck
Update to version 1.47 addresses the four critical CVEs and includes additional bug fixes.
Linuxsecurity
2026-07-16
CVE-2026-57075 published
Out-of-bounds read vulnerability in base64 decoder due to signed-char indexing.
Linuxsecurity
2026-07-16
CVE-2026-57076 published
Use-after-free vulnerability of an anchor key string shared between node and anchors table.
Linuxsecurity
2026-07-16
CVE-2026-57077 published
One-byte out-of-bounds read in lexer newline scan during block-scalar parsing.
Linuxsecurity
2026-07-16
CVE-2026-13713 published
Use-after-free / double-free vulnerability on anchor redefinition leading to remote-crash DoS.
Linuxsecurity

Community

Browse all →