Debian Package Tracker
Register | Log in
Subscribe

libfyaml

Choose email to subscribe with

general
  • source: libfyaml (main)
  • version: 0.9.4-1
  • maintainer: Jose Luis Blanco Claraco (DMD)
  • uploaders: Timo Röhling [DMD]
  • arch: any
  • std-ver: 4.7.3
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • oldstable: 0.7.12-2
  • stable: 0.8-1
  • testing: 0.9.4-1
  • unstable: 0.9.4-1
versioned links
  • 0.7.12-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 0.8-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 0.9.4-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • libfyaml-dev
  • libfyaml-utils
  • libfyaml0
action needed
A new upstream version is available: 1.0.0-beta1 high
A new upstream version 1.0.0-beta1 is available, you should consider packaging it.
Created: 2026-03-01 Last update: 2026-09-26 10:30
1 security issue in trixie high

There is 1 open security issue in trixie.

1 important issue:
  • CVE-2026-88359: libfyaml 0.9.6 contains a stack exhaustion vulnerability in fy_atom_iter_format(). When processing a specially crafted YAML document containing a very large literal or folded block scalar, the function repeatedly grows an internal buffer using alloca() inside a loop. The allocated stack memory is not released until the function returns, causing cumulative stack growth that can exceed the process stack limit and result in SIGSEGV and denial of service.
Created: 2026-09-25 Last update: 2026-09-25 11:30
1 security issue in sid high

There is 1 open security issue in sid.

1 important issue:
  • CVE-2026-88359: libfyaml 0.9.6 contains a stack exhaustion vulnerability in fy_atom_iter_format(). When processing a specially crafted YAML document containing a very large literal or folded block scalar, the function repeatedly grows an internal buffer using alloca() inside a loop. The allocated stack memory is not released until the function returns, causing cumulative stack growth that can exceed the process stack limit and result in SIGSEGV and denial of service.
Created: 2026-09-25 Last update: 2026-09-25 11:30
1 security issue in forky high

There is 1 open security issue in forky.

1 important issue:
  • CVE-2026-88359: libfyaml 0.9.6 contains a stack exhaustion vulnerability in fy_atom_iter_format(). When processing a specially crafted YAML document containing a very large literal or folded block scalar, the function repeatedly grows an internal buffer using alloca() inside a loop. The allocated stack memory is not released until the function returns, causing cumulative stack growth that can exceed the process stack limit and result in SIGSEGV and denial of service.
Created: 2026-09-25 Last update: 2026-09-25 11:30
1 security issue in bookworm high

There is 1 open security issue in bookworm.

1 important issue:
  • CVE-2026-88359: libfyaml 0.9.6 contains a stack exhaustion vulnerability in fy_atom_iter_format(). When processing a specially crafted YAML document containing a very large literal or folded block scalar, the function repeatedly grows an internal buffer using alloca() inside a loop. The allocated stack memory is not released until the function returns, causing cumulative stack growth that can exceed the process stack limit and result in SIGSEGV and denial of service.
Created: 2026-09-25 Last update: 2026-09-25 11:30
lintian reports 34 warnings normal
Lintian reports 34 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2025-09-24 Last update: 2026-02-13 11:35
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.4 instead of 4.7.3).
Created: 2026-03-31 Last update: 2026-03-31 15:01
news
[rss feed]
  • [2026-02-20] libfyaml 0.9.4-1 MIGRATED to testing (Debian testing watch)
  • [2026-02-12] Accepted libfyaml 0.9.4-1 (source) into unstable (Timo Röhling)
  • [2026-02-01] libfyaml 0.9.3-1 MIGRATED to testing (Debian testing watch)
  • [2026-01-27] Accepted libfyaml 0.9.3-1 (source) into unstable (Timo Röhling)
  • [2026-01-08] libfyaml 0.9.2-1 MIGRATED to testing (Debian testing watch)
  • [2026-01-02] Accepted libfyaml 0.9.2-1 (source) into unstable (Timo Röhling)
  • [2025-09-29] libfyaml 0.9-2 MIGRATED to testing (Debian testing watch)
  • [2025-09-24] Accepted libfyaml 0.9-2 (source) into unstable (Timo Röhling)
  • [2025-09-22] Accepted libfyaml 0.9-1 (source) into unstable (Timo Röhling)
  • [2023-06-24] libfyaml 0.8-1 MIGRATED to testing (Debian testing watch)
  • [2023-06-18] Accepted libfyaml 0.8-1 (source) into unstable (Timo Röhling)
  • [2022-12-28] libfyaml 0.7.12-2 MIGRATED to testing (Debian testing watch)
  • [2022-12-23] Accepted libfyaml 0.7.12-2 (source) into unstable (Timo Röhling)
  • [2022-02-28] libfyaml 0.7.12-1 MIGRATED to testing (Debian testing watch)
  • [2022-02-23] libfyaml 0.7.11-2 MIGRATED to testing (Debian testing watch)
  • [2022-02-22] Accepted libfyaml 0.7.12-1 (source) into unstable (Jose Luis Blanco Claraco) (signed by: Timo Röhling)
  • [2022-02-18] Accepted libfyaml 0.7.11-2 (source) into unstable (Timo Röhling)
  • [2022-02-18] Accepted libfyaml 0.7.11-1 (source amd64) into unstable, unstable (Debian FTP Masters) (signed by: Timo Röhling)
bugs [bug history graph]
  • all: 1
  • RC: 0
  • I&N: 1
  • M&W: 0
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian (0, 34)
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 0.9.4-1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing