VDB

GCVE-110-MAGEIA-2026-367

GCVE-110-MAGEIA-2026-367
Advisory Published
Vulnetix · Advisory published September 2, 2026
YAML::Syck versions before 1.47 for Perl allow a use-after-free and double-free via an anchor node freed while still on the parser value stack YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via a signed-char lookup-table index in syck_base64dec YAML::Syck versions before 1.47 for Perl allow a heap use-after-free via an anchor name reused as an anchors-table key in syck_hdlr_add_anchor YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via an unbounded newline scan in newline_len

Affected Products

VendorProductVersionsPlatforms
Mageiaperl-YAML-Syck0 (affected), 1.470.0-1.mga9 (unaffected)
Mageiaperl-YAML-Syck0 (affected), 1.470.0-1.mga10 (unaffected)

Browse GCVE Records

3,019 records in the GCVE database · Updated September 4, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›