Количество 10
Количество 10
CVE-2026-41401
libyang before 5.2.6 contains a heap use-after-free write vulnerability in lyd_parser_set_data_flags that incorrectly updates metadata list pointers when freeing non-head default metadata entries. Attackers can trigger this vulnerability by submitting crafted YANG XML documents with specific metadata attributes to applications parsing untrusted XML data, causing process crashes or potential code execution.
CVE-2026-41401
libyang before 5.2.6 contains a heap use-after-free write vulnerability in lyd_parser_set_data_flags that incorrectly updates metadata list pointers when freeing non-head default metadata entries. Attackers can trigger this vulnerability by submitting crafted YANG XML documents with specific metadata attributes to applications parsing untrusted XML data, causing process crashes or potential code execution.
CVE-2026-41401
libyang before 5.2.6 contains a heap use-after-free write vulnerability in lyd_parser_set_data_flags that incorrectly updates metadata list pointers when freeing non-head default metadata entries. Attackers can trigger this vulnerability by submitting crafted YANG XML documents with specific metadata attributes to applications parsing untrusted XML data, causing process crashes or potential code execution.
CVE-2026-41401
libyang - Heap Use-After-Free Write in XML Metadata Parsing
CVE-2026-41401
libyang before 5.2.6 contains a heap use-after-free write vulnerabilit ...
GHSA-v7jp-vmx6-5429
libyang before 5.2.6 contains a heap use-after-free write vulnerability in lyd_parser_set_data_flags that incorrectly updates metadata list pointers when freeing non-head default metadata entries. Attackers can trigger this vulnerability by submitting crafted YANG XML documents with specific metadata attributes to applications parsing untrusted XML data, causing process crashes or potential code execution.
openSUSE-SU-2026:21113-1
Security update for libyang
SUSE-SU-2026:2337-1
Security update for libyang
SUSE-SU-2026:2335-1
Security update for libyang
SUSE-SU-2026:2334-1
Security update for libyang
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-41401 libyang before 5.2.6 contains a heap use-after-free write vulnerability in lyd_parser_set_data_flags that incorrectly updates metadata list pointers when freeing non-head default metadata entries. Attackers can trigger this vulnerability by submitting crafted YANG XML documents with specific metadata attributes to applications parsing untrusted XML data, causing process crashes or potential code execution. | CVSS3: 6.5 | 1% Низкий | 2 месяца назад | |
CVE-2026-41401 libyang before 5.2.6 contains a heap use-after-free write vulnerability in lyd_parser_set_data_flags that incorrectly updates metadata list pointers when freeing non-head default metadata entries. Attackers can trigger this vulnerability by submitting crafted YANG XML documents with specific metadata attributes to applications parsing untrusted XML data, causing process crashes or potential code execution. | CVSS3: 6.5 | 1% Низкий | 2 месяца назад | |
CVE-2026-41401 libyang before 5.2.6 contains a heap use-after-free write vulnerability in lyd_parser_set_data_flags that incorrectly updates metadata list pointers when freeing non-head default metadata entries. Attackers can trigger this vulnerability by submitting crafted YANG XML documents with specific metadata attributes to applications parsing untrusted XML data, causing process crashes or potential code execution. | CVSS3: 6.5 | 1% Низкий | 2 месяца назад | |
CVE-2026-41401 libyang - Heap Use-After-Free Write in XML Metadata Parsing | CVSS3: 6.5 | 1% Низкий | 2 месяца назад | |
CVE-2026-41401 libyang before 5.2.6 contains a heap use-after-free write vulnerabilit ... | CVSS3: 6.5 | 1% Низкий | 2 месяца назад | |
GHSA-v7jp-vmx6-5429 libyang before 5.2.6 contains a heap use-after-free write vulnerability in lyd_parser_set_data_flags that incorrectly updates metadata list pointers when freeing non-head default metadata entries. Attackers can trigger this vulnerability by submitting crafted YANG XML documents with specific metadata attributes to applications parsing untrusted XML data, causing process crashes or potential code execution. | CVSS3: 6.5 | 1% Низкий | 2 месяца назад | |
openSUSE-SU-2026:21113-1 Security update for libyang | около 2 месяцев назад | |||
SUSE-SU-2026:2337-1 Security update for libyang | около 2 месяцев назад | |||
SUSE-SU-2026:2335-1 Security update for libyang | около 2 месяцев назад | |||
SUSE-SU-2026:2334-1 Security update for libyang | около 2 месяцев назад |
Уязвимостей на страницу