Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-86901.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-86901
Upstream
Published
2026-05-12T17:16:21Z
Modified
2026-08-30T05:24:52Z
Summary
CVE-2026-5089 affecting package perl-YAML-Syck 1.34-1
Details

YAML::Syck versions before 1.38 for Perl has an out-of-bounds read.

The base60 (sexagesimal) parsing code in perl_syck.h has a buffer underflow bug in both int#base60 and float#base60 handlers. When processing the leftmost segment of a colon-separated value (e.g., the 1 in 1:30:45), the inner while loop can decrement a pointer past the start of the string buffer:

while ( colon >= ptr && *colon != ':' )
{
    colon--;
}
if ( *colon == ':' ) *colon = '\0';  // colon may be ptr-1 here

When no colon is found (final/leftmost segment), colon becomes ptr-1, and the subsequent *colon dereference reads one byte before the allocated buffer.

References

Affected packages

Azure Linux:3 / perl-YAML-Syck

Package

Name
perl-YAML-Syck
Purl
pkg:rpm/azure-linux/perl-YAML-Syck

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
1.34-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-86901.json"