Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-44673

Опубликовано: 14 мая 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

libyang is a YANG data modeling language library. Prior to SO 5.2.15, lyb_read_string() in src/parser_lyb.c contains an integer overflow that results in a heap buffer overflow when parsing a maliciously crafted LYB binary blob. An attacker who can supply LYB data to any libyang consumer (NETCONF server, sysrepo, etc.) can trigger a crash or potential heap corruption. This vulnerability is fixed in SO 5.2.15.

A flaw was found in libyang, a YANG data modeling language library. An integer overflow in the lyb_read_string() function can lead to a heap buffer overflow when parsing a maliciously crafted LYB binary blob. A remote attacker, by supplying this malicious LYB data to any libyang consumer (such as a NETCONF server), could trigger a crash, resulting in a denial of service (DoS), or potentially achieve arbitrary code execution through heap corruption.

Отчет

This is an Important flaw in libyang, which could allow a remote attacker to cause a denial of service or potentially execute arbitrary code. The vulnerability arises from an integer overflow when processing a specially crafted LYB binary blob, impacting Red Hat products that consume libyang data, such as NETCONF servers.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Дополнительная информация

Статус:

Important
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2477617libyang: libyang: Denial of Service or arbitrary code execution via maliciously crafted LYB binary blob

EPSS

Процентиль: 35%
0.00428
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

libyang is a YANG data modeling language library. Prior to SO 5.2.15, lyb_read_string() in src/parser_lyb.c contains an integer overflow that results in a heap buffer overflow when parsing a maliciously crafted LYB binary blob. An attacker who can supply LYB data to any libyang consumer (NETCONF server, sysrepo, etc.) can trigger a crash or potential heap corruption. This vulnerability is fixed in SO 5.2.15.

CVSS3: 7.5
nvd
3 месяца назад

libyang is a YANG data modeling language library. Prior to SO 5.2.15, lyb_read_string() in src/parser_lyb.c contains an integer overflow that results in a heap buffer overflow when parsing a maliciously crafted LYB binary blob. An attacker who can supply LYB data to any libyang consumer (NETCONF server, sysrepo, etc.) can trigger a crash or potential heap corruption. This vulnerability is fixed in SO 5.2.15.

CVSS3: 7.5
msrc
2 месяца назад

libyang: lyb_read_string() integer overflow → heap buffer overflow

CVSS3: 7.5
debian
3 месяца назад

libyang is a YANG data modeling language library. Prior to SO 5.2.15, ...

suse-cvrf
около 2 месяцев назад

Security update for libyang

EPSS

Процентиль: 35%
0.00428
Низкий

7.5 High

CVSS3