libyara/grammar.y in YARA 3.5.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted rule that is mishandled in the yr_parser_lookup_loop_variable function.
https://github.com/VirusTotal/yara/commit/890c3f850293176c0e996a602ffa88b315f4e98f