Logo
vulnerabilityCVE-2026-41401
Name
CVE-2026-41401
Source
NVD ( link)Debian ( link)
Description
libyang before 5.2.6 contains a heap use-after-free write vulnerability in lyd_parser_set_data_flags that incorrectly updates metadata list pointers when freeing non-head default metadata entries. Attackers can trigger this vulnerability by submitting crafted YANG XML documents with specific metadata attributes to applications parsing untrusted XML data, causing process crashes or potential code execution.
Published Date
Updated Date
Workaround
-
Advisories

Analysis#


Affected Component
Analysis
libyang
Exploitable

Vulnerability Ratings#


7.1
CVSSv4
6.5
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
2.1.148
Exploitable
buildroot
master
3.13.6
Exploitable
openwrt
master
3.13.6-r1
Exploitable
yocto
kirkstone
2.0.164
Exploitable
yocto
master
3.13.6
Exploitable
yocto
scarthgap
2.1.148
Patched

Resolved with patches#


libyang (yocto:scarthgap)

#
Title
Author
Resolve
1
parser common BUGFIX invalid metadata removal
Michal Vasko <mvasko@cesnet.cz>
CVE-2026-41401