PT-2026-41121 · Libyang · Libyang
Dom-Omg
·
Published
2026-05-14
·
Updated
2026-05-28
·
CVE-2026-44673
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
libyang versions prior to 5.2.15
Description
The
lyb read string() function in src/parser lyb.c contains an integer overflow. This occurs when parsing a maliciously crafted LYB binary blob, leading to a heap buffer overflow. An attacker capable of supplying LYB data to a libyang consumer, such as a NETCONF server or sysrepo, can cause a crash or heap corruption.Recommendations
Update to version 5.2.15.
Exploit
Fix
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Libyang