Описание
Security update for libyang
This update for libyang fixes the following issue
- CVE-2026-44673: integer overflow in
lyb_read_string()ofsrc/parser_lyb.cleads to heap buffer overflow when parsing a maliciously crafted LYB binary blob (bsc#1265330).
Список пакетов
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS
libyang-extentions-1.0.184-150300.3.9.1
libyang1-1.0.184-150300.3.9.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS
libyang-extentions-1.0.184-150300.3.9.1
libyang1-1.0.184-150300.3.9.1
SUSE Linux Enterprise Server 15 SP4-LTSS
libyang-extentions-1.0.184-150300.3.9.1
libyang1-1.0.184-150300.3.9.1
SUSE Linux Enterprise Server for SAP Applications 15 SP4
libyang-extentions-1.0.184-150300.3.9.1
libyang1-1.0.184-150300.3.9.1
Ссылки
- Link for SUSE-SU-2026:2381-1
- E-Mail link for SUSE-SU-2026:2381-1
- SUSE Security Ratings
- SUSE Bug 1265330
- SUSE CVE CVE-2026-44673 page
Описание
libyang is a YANG data modeling language library. Prior to SO 5.2.15, lyb_read_string() in src/parser_lyb.c contains an integer overflow that results in a heap buffer overflow when parsing a maliciously crafted LYB binary blob. An attacker who can supply LYB data to any libyang consumer (NETCONF server, sysrepo, etc.) can trigger a crash or potential heap corruption. This vulnerability is fixed in SO 5.2.15.
Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:libyang-extentions-1.0.184-150300.3.9.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:libyang1-1.0.184-150300.3.9.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS:libyang-extentions-1.0.184-150300.3.9.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS:libyang1-1.0.184-150300.3.9.1
Ссылки
- CVE-2026-44673
- SUSE Bug 1265330