- Package:
- src:yaml-cpp
- Source:
- src:yaml-cpp
- Submitter:
- Salvatore Bonaccorso
- Date:
- 2026-09-26 18:49:02 UTC
- Severity:
- normal
- Tags:
Hi, The following vulnerability was published for yaml-cpp. CVE-2026-75432[0]: | An issue in yaml-cpp 0.9.0 allows a remote attacker to obtain | sensitive information via the src/scanner.cpp, Scanner::PopIndent(), | and Scanner::PushIndentTo() components If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-75432 https://www.cve.org/CVERecord?id=CVE-2026-75432 [1] https://github.com/jbeder/yaml-cpp/issues/1475 [2] https://github.com/jbeder/yaml-cpp/pull/1476 [3] https://github.com/jbeder/yaml-cpp/commit/8b2e6ba3288de15ed7a61d5c89cde2ed47327c1e Please adjust the affected versions in the BTS as needed. Regards, Salvatore
Hi Salvatore, Please mark yaml-cpp <not-affected> for bookworm, trixie, and sid. No upload is planned. The crash is an empty indent-stack pop in Scanner::PopIndent(). Upstream introduced it in c7a86c0 (PR #1468, 2026-07-30), *after* the yaml-cpp-0.9.0 tag (56e3bb5, 2026-02-04). That commit is not in the 0.9.0 tarball. I ran the public inputs against the archive versions: bookworm 0.7.0+dfsg-8+b1 ParserException (the 96-byte sample parses) trixie 0.8.0+dfsg-7 ParserException sid 0.9.0+dfsg-9 ParserException None of them abort. Those inputs do abort on upstream 3eb39d5, which is after #1468 and before #1476: UndefinedBehaviorSanitizer in PopIndent(), and SIGSEGV. The MITRE text describes an information leak in 0.9.0. What reproduces is a crash on master snapshots from 30 July to 10 August 2026. No Debian suite is in that window. Please let me know if you have any questions, or if this still needs to be fixed after all. Best regards, Simon Quigley tsimonq2@debian.org
Hi Simon, Yes, agreed, the issue is introduced with https://github.com/jbeder/yaml-cpp/commit/c7a86c0e1f4868abebab474a6a3e19cf27ebfaac , so I have updated the tracker information on the CVE. Regards, Salvatore