GHSA-3qj9-89fg-m5cwMediumCVSS 6.5
libfyaml 0.9.6 contains a stack exhaustion vulnerability in fy_atom_iter_format(). When...
🔗 CVE IDs covered (1)
📋 Description
libfyaml 0.9.6 contains a stack exhaustion vulnerability in fy_atom_iter_format(). When processing a specially crafted YAML document containing a very large literal or folded block scalar, the function repeatedly grows an internal buffer using alloca() inside a loop. The allocated stack memory is not released until the function returns, causing cumulative stack growth that can exceed the process stack limit and result in SIGSEGV and denial of service.
🔗 References (5)
- https://nvd.nist.gov/vuln/detail/CVE-2026-88359
- https://github.com/pantoniou/libfyaml/issues/315
- https://github.com/pantoniou/libfyaml/commit/20502068902d58c076da873117985798df2c7e74
- https://github.com/pantoniou/libfyaml/commit/93741a7c9331da9da65ef7a25f2d7d6a817a1c29
- https://github.com/advisories/GHSA-3qj9-89fg-m5cw