Back

HIGH

YAML::Syck versions before 1.38 for Perl has an out-of-bounds read

Published May 12, 2026

Description

YAML::Syck versions before 1.38 for Perl has an out-of-bounds read.

The base60 (sexagesimal) parsing code in perl_syck.h has a buffer underflow bug in both int#base60 and float#base60 handlers. When processing the leftmost segment of a colon-separated value (e.g., the 1 in 1:30:45), the inner while loop can decrement a pointer past the start of the string buffer:

while ( colon >= ptr && *colon != ':' ) { colon--; } if ( *colon == ':' ) *colon = '\0'; // colon may be ptr-1 here

When no colon is found (final/leftmost segment), colon becomes ptr-1, and the subsequent *colon dereference reads one byte before the allocated buffer.

Affected products

Remediation

Vendor solution

Upgrade to YAML::Syck version 1.38 or later.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

References (10)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner CPANSec
Published May 12, 2026
Updated May 14, 2026
Reserved Mar 28, 2026

CISA Vulnrichment

Updated May 14, 2026

NVD

Status Deferred
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date May 12, 2026
Bugzilla 2476554

ENISA EUVD

Assigner CPANSec
Published May 12, 2026
Updated May 14, 2026

GitHub

No data