Описание
ELSA-2026-24758: libyang security update (IMPORTANT)
[2.1.148-4]
- DoS or arbitrary code execution via maliciously crafted LYB binary blob
- Resolves: RHEL-177026 - CVE-2026-44673
Обновленные пакеты
Oracle Linux 10
Oracle Linux aarch64
libyang
2.1.148-4.el10_2
libyang-devel
2.1.148-4.el10_2
libyang-devel-doc
2.1.148-4.el10_2
Oracle Linux x86_64
libyang
2.1.148-4.el10_2
libyang-devel
2.1.148-4.el10_2
libyang-devel-doc
2.1.148-4.el10_2
Связанные CVE
Связанные уязвимости
libyang is a YANG data modeling language library. Prior to SO 5.2.15, lyb_read_string() in src/parser_lyb.c contains an integer overflow that results in a heap buffer overflow when parsing a maliciously crafted LYB binary blob. An attacker who can supply LYB data to any libyang consumer (NETCONF server, sysrepo, etc.) can trigger a crash or potential heap corruption. This vulnerability is fixed in SO 5.2.15.
libyang is a YANG data modeling language library. Prior to SO 5.2.15, lyb_read_string() in src/parser_lyb.c contains an integer overflow that results in a heap buffer overflow when parsing a maliciously crafted LYB binary blob. An attacker who can supply LYB data to any libyang consumer (NETCONF server, sysrepo, etc.) can trigger a crash or potential heap corruption. This vulnerability is fixed in SO 5.2.15.
libyang is a YANG data modeling language library. Prior to SO 5.2.15, lyb_read_string() in src/parser_lyb.c contains an integer overflow that results in a heap buffer overflow when parsing a maliciously crafted LYB binary blob. An attacker who can supply LYB data to any libyang consumer (NETCONF server, sysrepo, etc.) can trigger a crash or potential heap corruption. This vulnerability is fixed in SO 5.2.15.
libyang: lyb_read_string() integer overflow → heap buffer overflow
libyang is a YANG data modeling language library. Prior to SO 5.2.15, ...