Описание
ELSA-2026-24545: libyang security update (IMPORTANT)
[1.0.184-2]
- DoS or arbitrary code execution via maliciously crafted LYB binary blob
- Resolves: RHEL-177017 - CVE-2026-44673
Обновленные пакеты
Oracle Linux 8
Oracle Linux aarch64
libyang
1.0.184-2.el8_10
Oracle Linux x86_64
libyang
1.0.184-2.el8_10
Связанные CVE
Связанные уязвимости
libyang is a YANG data modeling language library. Prior to SO 5.2.15, lyb_read_string() in src/parser_lyb.c contains an integer overflow that results in a heap buffer overflow when parsing a maliciously crafted LYB binary blob. An attacker who can supply LYB data to any libyang consumer (NETCONF server, sysrepo, etc.) can trigger a crash or potential heap corruption. This vulnerability is fixed in SO 5.2.15.
libyang is a YANG data modeling language library. Prior to SO 5.2.15, lyb_read_string() in src/parser_lyb.c contains an integer overflow that results in a heap buffer overflow when parsing a maliciously crafted LYB binary blob. An attacker who can supply LYB data to any libyang consumer (NETCONF server, sysrepo, etc.) can trigger a crash or potential heap corruption. This vulnerability is fixed in SO 5.2.15.
libyang is a YANG data modeling language library. Prior to SO 5.2.15, lyb_read_string() in src/parser_lyb.c contains an integer overflow that results in a heap buffer overflow when parsing a maliciously crafted LYB binary blob. An attacker who can supply LYB data to any libyang consumer (NETCONF server, sysrepo, etc.) can trigger a crash or potential heap corruption. This vulnerability is fixed in SO 5.2.15.
libyang: lyb_read_string() integer overflow → heap buffer overflow
libyang is a YANG data modeling language library. Prior to SO 5.2.15, ...