Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-79977.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-79977
Upstream
Published
2026-03-16T23:16:21Z
Modified
2026-08-30T05:24:52Z
Summary
CVE-2026-4177 affecting package perl-YAML-Syck 1.34-1
Details

YAML::Syck versions through 1.36 for Perl has several potential security vulnerabilities including a high-severity heap buffer overflow in the YAML emitter.

The heap overflow occurs when class names exceed the initial 512-byte allocation.

The base64 decoder could read past the buffer end on trailing newlines.

strtok mutated n->type_id in place, corrupting shared node data.

A memory leak occurred in syckhdlradd_anchor when a node already had an anchor. The incoming anchor string 'a' was leaked on early return.

References

Affected packages

Azure Linux:3 / perl-YAML-Syck

Package

Name
perl-YAML-Syck
Purl
pkg:rpm/azure-linux/perl-YAML-Syck

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
1.34-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-79977.json"