{"id":"UBUNTU-CVE-2024-35328","details":"libyaml v0.2.5 is vulnerable to DDOS. Affected by this issue is the function yaml_parser_parse of the file /src/libyaml/src/parser.c.","modified":"2026-02-04T04:29:00.702401Z","published":"2024-06-13T16:15:00Z","withdrawn":"2025-06-23T15:58:13Z","related":["CVE-2024-35328"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-35328"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2024-35328"},{"type":"REPORT","url":"https://github.com/idhyt/pocs/blob/main/libyaml/CVE-2024-35328.c"},{"type":"REPORT","url":"https://github.com/yaml/libyaml/issues/298#issuecomment-2167684233"},{"type":"REPORT","url":"https://github.com/yaml/libyaml/issues/302"}],"affected":[{"package":{"name":"libyaml","ecosystem":"Ubuntu:Pro:14.04:LTS","purl":"pkg:deb/ubuntu/libyaml?arch=src?distro=trusty/esm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.1.4-2build1","0.1.4-2ubuntu1","0.1.4-3ubuntu1","0.1.4-3ubuntu2","0.1.4-3ubuntu3","0.1.4-3ubuntu3.1"],"ecosystem_specific":{"ubuntu_priority":"medium"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-35328.json"}},{"package":{"name":"golang-yaml.v2","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/golang-yaml.v2?arch=src?distro=esm-infra/xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.0+git20150627.7ad95dd-1","0.0+git20160301.0.a83829b-1","0.0+git20160301.0.a83829b-1ubuntu0.1~esm1"],"ecosystem_specific":{"ubuntu_priority":"medium"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-35328.json"}},{"package":{"name":"libyaml","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/libyaml?arch=src?distro=esm-infra/xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.1.6-3"],"ecosystem_specific":{"ubuntu_priority":"medium"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-35328.json"}},{"package":{"name":"libyaml-libyaml-perl","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/libyaml-libyaml-perl?arch=src?distro=esm-infra/xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.41-6","0.41-6build1"],"ecosystem_specific":{"ubuntu_priority":"medium"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-35328.json"}},{"package":{"name":"golang-goyaml","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/golang-goyaml?arch=src?distro=esm-apps/xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.0~bzr50-1"],"ecosystem_specific":{"ubuntu_priority":"medium"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-35328.json"}},{"package":{"name":"libyaml","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/libyaml?arch=src?distro=esm-infra/bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.1.7-2ubuntu3"],"ecosystem_specific":{"ubuntu_priority":"medium"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-35328.json"}},{"package":{"name":"libyaml-libyaml-perl","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/libyaml-libyaml-perl?arch=src?distro=esm-infra/bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.63-2build1","0.69+repack-1"],"ecosystem_specific":{"ubuntu_priority":"medium"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-35328.json"}},{"package":{"name":"golang-yaml.v2","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/golang-yaml.v2?arch=src?distro=esm-apps/bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.0+git20170407.0.cd8b52f-1ubuntu1","0.0+git20170407.0.cd8b52f-1ubuntu2","0.0+git20170407.0.cd8b52f-1ubuntu2+esm1"],"ecosystem_specific":{"ubuntu_priority":"medium"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-35328.json"}},{"package":{"name":"golang-yaml.v2","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/golang-yaml.v2?arch=src?distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.2.2-1","2.2.2-1ubuntu0.1"],"ecosystem_specific":{"ubuntu_priority":"medium"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-35328.json"}},{"package":{"name":"libyaml","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/libyaml?arch=src?distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.2.1-1","0.2.2-1"],"ecosystem_specific":{"ubuntu_priority":"medium"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-35328.json"}},{"package":{"name":"libyaml-libyaml-perl","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/libyaml-libyaml-perl?arch=src?distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.80+repack-1","0.80+repack-1build1","0.80+repack-2","0.81+repack-1"],"ecosystem_specific":{"ubuntu_priority":"medium"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-35328.json"}},{"package":{"name":"golang-yaml.v2","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/golang-yaml.v2?arch=src?distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.4.0-1","2.4.0-2"],"ecosystem_specific":{"ubuntu_priority":"medium"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-35328.json"}},{"package":{"name":"libyaml","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/libyaml?arch=src?distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.2.2-1","0.2.2-1build1","0.2.2-1build2"],"ecosystem_specific":{"ubuntu_priority":"medium"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-35328.json"}},{"package":{"name":"libyaml-libyaml-perl","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/libyaml-libyaml-perl?arch=src?distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.82+repack-1build1","0.82+repack-1build2","0.83+ds-1","0.83+ds-1build1"],"ecosystem_specific":{"ubuntu_priority":"medium"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-35328.json"}},{"package":{"name":"golang-yaml.v2","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/golang-yaml.v2?arch=src?distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.4.0-4"],"ecosystem_specific":{"ubuntu_priority":"medium"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-35328.json"}},{"package":{"name":"libyaml","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/libyaml?arch=src?distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.2.5-1","0.2.5-1build1"],"ecosystem_specific":{"ubuntu_priority":"medium"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-35328.json"}},{"package":{"name":"libyaml-libyaml-perl","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/libyaml-libyaml-perl?arch=src?distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.86+ds-1","0.89+ds-1","0.89+ds-1build1","0.89+ds-1build2"],"ecosystem_specific":{"ubuntu_priority":"medium"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-35328.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}