Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-44673

Опубликовано: 14 мая 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 7.5

Описание

libyang is a YANG data modeling language library. Prior to SO 5.2.15, lyb_read_string() in src/parser_lyb.c contains an integer overflow that results in a heap buffer overflow when parsing a maliciously crafted LYB binary blob. An attacker who can supply LYB data to any libyang consumer (NETCONF server, sysrepo, etc.) can trigger a crash or potential heap corruption. This vulnerability is fixed in SO 5.2.15.

РелизСтатусПримечание
devel

not-affected

see notes
esm-apps/focal

not-affected

see notes
esm-apps/jammy

not-affected

see notes
jammy

not-affected

see notes
noble

DNE

questing

not-affected

see notes
resolute

not-affected

see notes
upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

jammy

not-affected

see notes
noble

not-affected

see notes
questing

DNE

resolute

DNE

upstream

needs-triage

Показывать по

EPSS

Процентиль: 35%
0.00428
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
3 месяца назад

libyang is a YANG data modeling language library. Prior to SO 5.2.15, lyb_read_string() in src/parser_lyb.c contains an integer overflow that results in a heap buffer overflow when parsing a maliciously crafted LYB binary blob. An attacker who can supply LYB data to any libyang consumer (NETCONF server, sysrepo, etc.) can trigger a crash or potential heap corruption. This vulnerability is fixed in SO 5.2.15.

CVSS3: 7.5
nvd
3 месяца назад

libyang is a YANG data modeling language library. Prior to SO 5.2.15, lyb_read_string() in src/parser_lyb.c contains an integer overflow that results in a heap buffer overflow when parsing a maliciously crafted LYB binary blob. An attacker who can supply LYB data to any libyang consumer (NETCONF server, sysrepo, etc.) can trigger a crash or potential heap corruption. This vulnerability is fixed in SO 5.2.15.

CVSS3: 7.5
msrc
2 месяца назад

libyang: lyb_read_string() integer overflow → heap buffer overflow

CVSS3: 7.5
debian
3 месяца назад

libyang is a YANG data modeling language library. Prior to SO 5.2.15, ...

suse-cvrf
около 2 месяцев назад

Security update for libyang

EPSS

Процентиль: 35%
0.00428
Низкий

7.5 High

CVSS3