GHSA-3qj9-89fg-m5cwMediumCVSS 6.5

libfyaml 0.9.6 contains a stack exhaustion vulnerability in fy_atom_iter_format(). When...

Published
September 24, 2026
Last Modified
September 25, 2026

🔗 CVE IDs covered (1)

📋 Description

libfyaml 0.9.6 contains a stack exhaustion vulnerability in fy_atom_iter_format(). When processing a specially crafted YAML document containing a very large literal or folded block scalar, the function repeatedly grows an internal buffer using alloca() inside a loop. The allocated stack memory is not released until the function returns, causing cumulative stack growth that can exceed the process stack limit and result in SIGSEGV and denial of service.

🔗 References (5)