Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:67269 - Security Advisory
Issued:
2026-09-14
Updated:
2026-09-14

RHSA-2026:67269 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: perl-YAML-Syck security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for perl-YAML-Syck is now available for Red Hat Enterprise Linux 8.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

This module provides a Perl interface to the libsyck data serialization library. It exports the Dump and Load functions for converting Perl data structures to YAML strings, and the other way around.

Security Fix(es):

  • YAML-Syck: YAML::Syck: Denial of Service via crafted YAML document (CVE-2026-13713)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat CodeReady Linux Builder for x86_64 8 x86_64
  • Red Hat CodeReady Linux Builder for Power, little endian 8 ppc64le
  • Red Hat CodeReady Linux Builder for ARM 64 8 aarch64
  • Red Hat CodeReady Linux Builder for IBM z Systems 8 s390x

Fixes

  • BZ - 2501564 - CVE-2026-13713 YAML-Syck: YAML::Syck: Denial of Service via crafted YAML document

CVEs

  • CVE-2026-13713

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat CodeReady Linux Builder for x86_64 8

SRPM
perl-YAML-Syck-1.30-7.el8_10.src.rpm SHA-256: 52bc1749cb6bf9069cfb82b5cb24f84db731aea1dd67ea3aedde2962c361ef9b
x86_64
perl-YAML-Syck-1.30-7.el8_10.x86_64.rpm SHA-256: 8cd2047880e0747dc50a21c14aab5563dde14eb6ec556b28f36e8e21d8f4ad95
perl-YAML-Syck-debuginfo-1.30-7.el8_10.x86_64.rpm SHA-256: 0c86a83df78fdd4003d017d0a01660c2ea07cf120978a97f1d9b1bf019edbf72
perl-YAML-Syck-debugsource-1.30-7.el8_10.x86_64.rpm SHA-256: 1384ee5e65bbd2bafc0e6cc9e7e70c2603c5a7704d2e319e1087a9dc9368cdca

Red Hat CodeReady Linux Builder for Power, little endian 8

SRPM
perl-YAML-Syck-1.30-7.el8_10.src.rpm SHA-256: 52bc1749cb6bf9069cfb82b5cb24f84db731aea1dd67ea3aedde2962c361ef9b
ppc64le
perl-YAML-Syck-1.30-7.el8_10.ppc64le.rpm SHA-256: d9ea7ccf5be71275b8ba3be8118962102bb5bf24bb7f147c19beec15fa597abb
perl-YAML-Syck-debuginfo-1.30-7.el8_10.ppc64le.rpm SHA-256: 044f97b3abfd0c96532a080abd0a1f93a42bd9efd0df9030f475dfc9318bb9ab
perl-YAML-Syck-debugsource-1.30-7.el8_10.ppc64le.rpm SHA-256: e9799ca3bdf9e7ab26643d22fc65d78bc45988e7cbb300023ec7c54c2e367071

Red Hat CodeReady Linux Builder for ARM 64 8

SRPM
perl-YAML-Syck-1.30-7.el8_10.src.rpm SHA-256: 52bc1749cb6bf9069cfb82b5cb24f84db731aea1dd67ea3aedde2962c361ef9b
aarch64
perl-YAML-Syck-1.30-7.el8_10.aarch64.rpm SHA-256: 436325abb25edcee222d454eff109f78e7885f25b14ec4fcc70721766ade150c
perl-YAML-Syck-debuginfo-1.30-7.el8_10.aarch64.rpm SHA-256: 721a645ba03389194e3f67305f6c6210eafb494ae320bb93b5da88b983c493de
perl-YAML-Syck-debugsource-1.30-7.el8_10.aarch64.rpm SHA-256: e218052f2d26ade8f969bcc6accf30fb888260da7b900c7f128f73b0e249176b

Red Hat CodeReady Linux Builder for IBM z Systems 8

SRPM
perl-YAML-Syck-1.30-7.el8_10.src.rpm SHA-256: 52bc1749cb6bf9069cfb82b5cb24f84db731aea1dd67ea3aedde2962c361ef9b
s390x
perl-YAML-Syck-1.30-7.el8_10.s390x.rpm SHA-256: 52c2cda398a13a002199c142fabeffb28a2c8223e960fbe6510873b219713725
perl-YAML-Syck-debuginfo-1.30-7.el8_10.s390x.rpm SHA-256: 088cb0a982d461d09e4f415a8a951d6558f352ff884761ca7c958d3beda98aa0
perl-YAML-Syck-debugsource-1.30-7.el8_10.s390x.rpm SHA-256: debf5f6218d6a8680cc93f4a7ea18dbb12b99a5520630be370547e124486a55f

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility