{"id":"AZL-79977","summary":"CVE-2026-4177 affecting package perl-YAML-Syck 1.34-1","details":"YAML::Syck versions through 1.36 for Perl has several potential security vulnerabilities including a high-severity heap buffer overflow in the YAML emitter.\n\nThe heap overflow occurs when class names exceed the initial 512-byte allocation.\n\nThe base64 decoder could read past the buffer end on trailing newlines.\n\nstrtok mutated n-\u003etype_id in place, corrupting shared node data.\n\nA memory leak occurred in syck_hdlr_add_anchor when a node already had an anchor. The incoming anchor string 'a' was leaked on early return.","modified":"2026-09-03T05:28:38Z","published":"2026-03-16T23:16:21Z","upstream":["CVE-2026-4177"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-4177"}],"affected":[{"package":{"name":"perl-YAML-Syck","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/perl-YAML-Syck"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.34-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-79977.json"}}],"schema_version":"1.9.0"}