CVE-2024-3205

Publication date 2 April 2024

Last updated 24 July 2024


Ubuntu priority

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: The maintainer identified an error in the libyaml fuzzers. It is not possible to reproduce nor exploit the issue.

Read the notes from the security team

Notes


jdstrand

golang-goyaml is a go translation of libyaml and shouldn’t share implementation flaws, but may share design flaws


sbeattie

as of 2024-04-15, fix has not landed upstream.


mdeslaur

libyaml-libyaml-perl, golang-goyaml, and golang-yaml.v2 are unrelated codebases. This appears to be an issue with the fuzzer, not libyaml itself: https://github.com/yaml/libyaml/issues/258#issuecomment-2058613931 The libyaml project doesn’t think this CVE should be. Marking as not-affected.

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
libyaml