Fedora Account System
Red Hat Associate
Red Hat Customer
libyang is a YANG data modeling language library. Prior to SO 5.2.15, lyb_read_string() in src/parser_lyb.c contains an integer overflow that results in a heap buffer overflow when parsing a maliciously crafted LYB binary blob. An attacker who can supply LYB data to any libyang consumer (NETCONF server, sysrepo, etc.) can trigger a crash or potential heap corruption. This vulnerability is fixed in SO 5.2.15.
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:24545 https://access.redhat.com/errata/RHSA-2026:24545
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:24758 https://access.redhat.com/errata/RHSA-2026:24758
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:25051 https://access.redhat.com/errata/RHSA-2026:25051
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:49666 https://access.redhat.com/errata/RHSA-2026:49666
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:51339 https://access.redhat.com/errata/RHSA-2026:51339
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:51351 https://access.redhat.com/errata/RHSA-2026:51351
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On Via RHSA-2026:51368 https://access.redhat.com/errata/RHSA-2026:51368