Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Debian LTS 1.34-1 libyaml-syck-perl Critical Buffer Overflow CVE-2025-11683

debian lts
Calendar Grey April 9, 2026
Dist Debian Esm H88
Critical update on libyaml-syck-perl for Debian addressing high-severity issues like buffer overflow and out-of-bounds reads.
Brief introduction CVE-2025-11683 Missing null terminators in token.c leads to but-of-bounds read which allows adjacent variable to be read

Summary

CVE-2025-11683

Missing null terminators in token.c leads to but-of-bounds read
which allows adjacent variable to be read. The issue is seen with
complex YAML files with a hash of all keys and empty values.

CVE-2026-4177

Several security vulnerabilities including a high-severity heap
buffer overflow in the YAML emitter. The heap overflow occurs when
class names exceed the initial 512-byte allocation. The base64
decoder could read past the buffer end on trailing newlines. strtok
mutated n->type_id in place, corrupting shared node data. A memory
leak occurred in syck_hdlr_add_anchor when a node already had an
anchor. The incoming anchor string 'a' was leaked on early return.

For Debian 11 bullseye, these problems have been fixed in version
1.34-1+deb11u1.

We recommend that you upgrade your libyaml-syck-perl packages.

For the detailed security status of libyaml-syck-perl please refer to
its security tracker page at:

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: libyaml-syck-perl
Version: 1.34-1+deb11u1
CVE ID: CVE-2025-11683 CVE-2026-4177

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here