VDB
GCVE-110-MAGEIA-2026-367
GCVE-110-MAGEIA-2026-367
Advisory Published
YAML::Syck versions before 1.47 for Perl allow a use-after-free and
double-free via an anchor node freed while still on the parser value
stack
YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via
a signed-char lookup-table index in syck_base64dec
YAML::Syck versions before 1.47 for Perl allow a heap use-after-free via
an anchor name reused as an anchors-table key in syck_hdlr_add_anchor
YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via
an unbounded newline scan in newline_len
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | perl-YAML-Syck | 0 (affected), 1.470.0-1.mga9 (unaffected) | — |
| Mageia | perl-YAML-Syck | 0 (affected), 1.470.0-1.mga10 (unaffected) | — |
References
Browse GCVE Records
3,019 records in the GCVE database · Updated September 4, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.