Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:67269: Important: perl-YAML-Syck security update

A denial-of-service vulnerability (CVE-2026-13713, CVSS 6.2) exists in the perl-YAML-Syck module where a crafted YAML document can cause the application to crash. The vulnerability affects the libsyck data serialization library interface in Red Hat Enterprise Linux 8. Red Hat has released a security update rated Important to address this issue.
Read Full Article →

Red Hat Product Errata RHSA-2026:67269 - Security Advisory Issued: 2026-09-14 Updated: 2026-09-14 RHSA-2026:67269 - Security Advisory Overview Updated Packages Synopsis Important: perl-YAML-Syck security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for perl-YAML-Syck is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description This module provides a Perl interface to the libsyck data serialization library. It exports the Dump and Load functions for converting Perl data structures to YAML strings, and the other way around. Security Fix(es): YAML-Syck: YAML::Syck: Denial of Service via crafted YAML document (CVE-2026-13713) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat CodeReady Linux Builder for x86_64 8 x86_64 Red Hat CodeReady Linux Builder for Power, little endian 8 ppc64le Red Hat CodeReady Linux Builder for ARM 64 8 aarch64 Red Hat CodeReady Linux Builder for IBM z Systems 8 s390x Fixes BZ - 2501564 - CVE-2026-13713 YAML-Syck: YAML::Syck: Denial of Service via crafted YAML document CVEs CVE-2026-13713 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat CodeReady Linux Builder for x86_64 8 SRPM perl-YAML-Syck-1.30-7.el8_10.src.rpm SHA-256: 52bc1749cb6bf9069cfb82b5cb24f84db731aea1dd67ea3aedde2962c361ef9b x86_64 perl-YAML-Syck-1.30-7.el8_10.x86_64.rpm SHA-256: 8cd2047880e0747dc50a21c14aab5563dde14eb6ec556b28f36e8e21d8f4ad95 perl-YAML-Syck-debuginfo-1.30-7.el8_10.x86_64.rpm SHA-256: 0c86a83df78fdd4003d017d0a01660c2ea07cf120978a97f1d9b1bf019edbf72 perl-YAML-Syck-debugsource-1.30-7.el8_10.x86_64.rpm SHA-256: 1384ee5e65bbd2bafc0e6cc9e7e70c2603c5a7704d2e319e1087a9dc9368cdca Red Hat CodeReady Linux Builder for Power, little endian 8 SRPM perl-YAML-Syck-1.30-7.el8_10.src.rpm SHA-256: 52bc1749cb6bf9069cfb82b5cb24f84db731aea1dd67ea3aedde2962c361ef9b ppc64le perl-YAML-Syck-1.30-7.el8_10.ppc64le.rpm SHA-256: d9ea7ccf5be71275b8ba3be8118962102bb5bf24bb7f147c19beec15fa597abb perl-YAML-Syck-debuginfo-1.30-7.el8_10.ppc64le.rpm SHA-256: 044f97b3abfd0c96532a080abd0a1f93a42bd9efd0df9030f475dfc9318bb9ab perl-YAML-Syck-debugsource-1.30-7.el8_10.ppc64le.rpm SHA-256: e9799ca3bdf9e7ab26643d22fc65d78bc45988e7cbb300023ec7c54c2e367071 Red Hat CodeReady Linux Builder for ARM 64 8 SRPM perl-YAML-Syck-1.30-7.el8_10.src.rpm SHA-256: 52bc1749cb6bf9069cfb82b5cb24f84db731aea1dd67ea3aedde2962c361ef9b aarch64 perl-YAML-Syck-1.30-7.el8_10.aarch64.rpm SHA-256: 436325abb25edcee222d454eff109f78e7885f25b14ec4fcc70721766ade150c perl-YAML-Syck-debuginfo-1.30-7.el8_10.aarch64.rpm SHA-256: 721a645ba03389194e3f67305f6c6210eafb494ae320bb93b5da88b983c493de perl-YAML-Syck-debugsource-1.30-7.el8_10.aarch64.rpm SHA-256: e218052f2d26ade8f969bcc6accf30fb888260da7b900c7f128f73b0e249176b Red Hat CodeReady Linux Builder for IBM z Systems 8 SRPM perl-YAML-Syck-1.30-7.el8_10.src.rpm SHA-256: 52bc1749cb6bf9069cfb82b5cb24f84db731aea1dd67ea3aedde2962c361ef9b s390x perl-YAML-Syck-1.30-7.el8_10.s390x.rpm SHA-256: 52c2cda398a13a002199c142fabeffb28a2c8223e960fbe6510873b219713725 perl-YAML-Syck-debuginfo-1.30-7.el8_10.s390x.rpm SHA-256: 088cb0a982d461d09e4f415a8a951d6558f352ff884761ca7c958d3beda98aa0 perl-YAML-Syck-debugsource-1.30-7.el8_10.s390x.rpm SHA-256: debf5f6218d6a8680cc93f4a7ea18dbb12b99a5520630be370547e124486a55f The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .

Share this article