Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:2381-1

Опубликовано: 12 июн. 2026
Источник: suse-cvrf

Описание

Security update for libyang

This update for libyang fixes the following issue

  • CVE-2026-44673: integer overflow in lyb_read_string() of src/parser_lyb.c leads to heap buffer overflow when parsing a maliciously crafted LYB binary blob (bsc#1265330).

Список пакетов

SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS
libyang-extentions-1.0.184-150300.3.9.1
libyang1-1.0.184-150300.3.9.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS
libyang-extentions-1.0.184-150300.3.9.1
libyang1-1.0.184-150300.3.9.1
SUSE Linux Enterprise Server 15 SP4-LTSS
libyang-extentions-1.0.184-150300.3.9.1
libyang1-1.0.184-150300.3.9.1
SUSE Linux Enterprise Server for SAP Applications 15 SP4
libyang-extentions-1.0.184-150300.3.9.1
libyang1-1.0.184-150300.3.9.1

Описание

libyang is a YANG data modeling language library. Prior to SO 5.2.15, lyb_read_string() in src/parser_lyb.c contains an integer overflow that results in a heap buffer overflow when parsing a maliciously crafted LYB binary blob. An attacker who can supply LYB data to any libyang consumer (NETCONF server, sysrepo, etc.) can trigger a crash or potential heap corruption. This vulnerability is fixed in SO 5.2.15.


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:libyang-extentions-1.0.184-150300.3.9.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:libyang1-1.0.184-150300.3.9.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS:libyang-extentions-1.0.184-150300.3.9.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS:libyang1-1.0.184-150300.3.9.1

Ссылки