YAML::Syck versions before 1.38 for Perl has an out-of-bounds read
Published May 12, 2026
7.3
HIGHCVSS 3.1
EPSS 0.42%
Description
YAML::Syck versions before 1.38 for Perl has an out-of-bounds read.
The base60 (sexagesimal) parsing code in perl_syck.h has a buffer underflow bug in both int#base60 and float#base60 handlers. When processing the leftmost segment of a colon-separated value (e.g., the 1 in 1:30:45), the inner while loop can decrement a pointer past the start of the string buffer:
while ( colon >= ptr && *colon != ':' ) { colon--; } if ( *colon == ':' ) *colon = '\0'; // colon may be ptr-1 here
When no colon is found (final/leftmost segment), colon becomes ptr-1, and the subsequent *colon dereference reads one byte before the allocated buffer.
Affected products
-
Affected
- ≥ 0, < 1.38
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Toddr | YAML::Syck | unaffected | Affected
|
No data.
No data.
Red Hat Enterprise Linux 6
perl-YAML-Syck
Fix deferred
Red Hat Enterprise Linux 8
perl-YAML-Syck
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | perl-YAML-Syck | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | perl-YAML-Syck | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to YAML::Syck version 1.38 or later.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
References (10)
- http://www.openwall.com/lists/oss-security/2026/05/12/16
- https://access.redhat.com/security/cve/CVE-2026-5089 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2476554 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-29543 Advisory
- https://github.com/cpan-authors/YAML-Syck/commit/208a4d3bd1b5cdb4a791a6e3905bd6bd45e9d005.patch patch
- https://github.com/cpan-authors/YAML-Syck/issues/132 exploitissue-tracking
- https://github.com/cpan-authors/YAML-Syck/pull/133 issue-tracking
- https://metacpan.org/release/TODDR/YAML-Syck-1.38/changes release-notes
- https://nvd.nist.gov/vuln/detail/CVE-2026-5089
- https://www.cve.org/CVERecord?id=CVE-2026-5089
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data