PT-2026-41121 · Libyang+1 · Libyang+1

·

CVE-2026-44673

·

Published

2026-05-14

·

Updated

2026-08-07

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions libyang versions prior to 5.2.15
Description The lyb read string() function in src/parser lyb.c contains an integer overflow. This occurs when parsing a maliciously crafted LYB binary blob, leading to a heap buffer overflow. An attacker capable of supplying LYB data to a libyang consumer, such as a NETCONF server or sysrepo, can cause a crash or heap corruption.
Recommendations Update to version 5.2.15.

Exploit

Fix

DoS

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:24545
ALSA-2026:24758
ALSA-2026:25051
AZL-86816
CVE-2026-44673
OPENSUSE-SU-2026:10880-1
OPENSUSE-SU-2026:21113-1
RHSA-2026:24545
RHSA-2026:24758
RHSA-2026:25051
RHSA-2026:49666
RHSA-2026:51339
RHSA-2026:51351
RHSA-2026:51368
SUSE-SU-2026:22200-1
SUSE-SU-2026:22208-1
SUSE-SU-2026:2334-1
SUSE-SU-2026:2335-1
SUSE-SU-2026:2337-1
SUSE-SU-2026:2381-1

Affected Products

Rocky Linux
Libyang