DEBIAN-CVE-2026-88359

Source
https://security-tracker.debian.org/tracker/CVE-2026-88359
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-88359.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-88359
Upstream
Published
2026-09-24T14:18:18Z
Modified
2026-09-25T11:00:08Z
Summary
[none]
Details

libfyaml 0.9.6 contains a stack exhaustion vulnerability in fy_atom_iter_format(). When processing a specially crafted YAML document containing a very large literal or folded block scalar, the function repeatedly grows an internal buffer using alloca() inside a loop. The allocated stack memory is not released until the function returns, causing cumulative stack growth that can exceed the process stack limit and result in SIGSEGV and denial of service.

References

Affected packages

Debian:12 / libfyaml

Package

Name
libfyaml
Purl
pkg:deb/debian/libfyaml?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.7.12-2
0.8-1
0.9-1
0.9-2
0.9.2-1
0.9.3-1
0.9.4-1

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-88359.json"

Debian:13 / libfyaml

Package

Name
libfyaml
Purl
pkg:deb/debian/libfyaml?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.8-1
0.9-1
0.9-2
0.9.2-1
0.9.3-1
0.9.4-1

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-88359.json"

Debian:14 / libfyaml

Package

Name
libfyaml
Purl
pkg:deb/debian/libfyaml?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.8-1
0.9-1
0.9-2
0.9.2-1
0.9.3-1
0.9.4-1

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-88359.json"