Fedora Account System
Red Hat Associate
Red Hat Customer
libyang is a YANG data modeling language library. Prior to SO 5.2.15, lyb_read_string() in src/parser_lyb.c contains an integer overflow that results in a heap buffer overflow when parsing a maliciously crafted LYB binary blob. An attacker who can supply LYB data to any libyang consumer (NETCONF server, sysrepo, etc.) can trigger a crash or potential heap corruption. This vulnerability is fixed in SO 5.2.15.
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:24545 https://access.redhat.com/errata/RHSA-2026:24545
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:24758 https://access.redhat.com/errata/RHSA-2026:24758
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:25051 https://access.redhat.com/errata/RHSA-2026:25051
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:49666 https://access.redhat.com/errata/RHSA-2026:49666