YAML::Syck versions before 1.36 for Perl has missing null-terminators which causes out-of-bounds read and potential information disclosure

Missing null terminators in token.c leads to but-of-bounds read which allows adjacent variable to be read

The issue is seen with complex YAML files with a hash of all keys and empty values.  There is no indication that the issue leads to accessing memory outside that allocated to the module.
Advisories

No advisories yet.

Fixes

Solution

Upgrade to version 1.36 or higher


Workaround

Apply the patch

History

Tue, 21 Oct 2025 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Perl
Perl perl
Perl yaml::syck
Vendors & Products Perl
Perl perl
Perl yaml::syck

Fri, 17 Oct 2025 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Thu, 16 Oct 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Oct 2025 00:45:00 +0000

Type Values Removed Values Added
Description YAML::Syck versions before 1.36 for Perl has missing null-terminators which causes out-of-bounds read and potential information disclosure Missing null terminators in token.c leads to but-of-bounds read which allows adjacent variable to be read The issue is seen with complex YAML files with a hash of all keys and empty values.  There is no indication that the issue leads to accessing memory outside that allocated to the module.
Title YAML::Syck versions before 1.36 for Perl has missing Null-Terminators which causes Out-of-Bounds Read and potential Information Disclosure
Weaknesses CWE-119
References

cve-icon MITRE

Status: PUBLISHED

Assigner: CPANSec

Published:

Updated: 2025-10-16T13:42:17.584Z

Reserved: 2025-10-13T12:35:07.822Z

Link: CVE-2025-11683

cve-icon Vulnrichment

Updated: 2025-10-16T13:42:05.706Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-10-16T01:15:32.890

Modified: 2025-10-16T15:28:59.610

Link: CVE-2025-11683

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-10-16T00:14:41Z

Links: CVE-2025-11683 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2025-10-21T09:40:49Z