Logo
vulnerabilityCVE-2026-44673
Name
CVE-2026-44673
Source
NVD ( link)Debian ( link)
Description
libyang is a YANG data modeling language library. Prior to SO 5.2.15, lyb_read_string() in src/parser_lyb.c contains an integer overflow that results in a heap buffer overflow when parsing a maliciously crafted LYB binary blob. An attacker who can supply LYB data to any libyang consumer (NETCONF server, sysrepo, etc.) can trigger a crash or potential heap corruption. This vulnerability is fixed in SO 5.2.15.
Published Date
Updated Date
Workaround
-
Advisories

Analysis#


Affected Component
Analysis
libyang
Patched

Vulnerability Ratings#


7.5
CVSSv31
7.5
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
2.1.148
Not Affected
buildroot
master
3.13.6
Not Affected
openwrt
master
3.13.6-r1
Not Affected
openwrt
openwrt-25.12
3.13.6-r1
Not Affected
yocto
kirkstone
2.0.164
Not Affected
yocto
master
3.13.6
Not Affected

Resolved with patches#


libyang (yocto:scarthgap)

#
Title
Author
Resolve
1
parser lyb BUGFIX integer overflow and OOM (#2513)
dominik blain <dominik@qreativelab.io>
CVE-2026-44673