PatchSiren cyber security CVE debrief
CVE-2026-44673 CESNET CVE debrief
libyang is vulnerable to a heap buffer overflow when parsing maliciously crafted LYB binary blobs. This issue, fixed in version SO 5.2.15, can lead to a crash or potential heap corruption if an attacker supplies LYB data to any libyang consumer. The vulnerability is caused by an integer overflow in the lyb_read_string() function in src/parser_lyb.c. Defenders managing systems that use libyang, especially those processing untrusted LYB data, should assess exposure and prioritize patching to prevent potential crashes or heap corruption.
- Vendor
- CESNET
- Product
- libyang
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-14
- Original CVE updated
- 2026-09-09
- Advisory published
- 2026-05-14
- Advisory updated
- 2026-09-09
Who should care
Defenders managing systems that use libyang, especially those processing untrusted LYB data, should assess exposure and prioritize patching to prevent potential crashes or heap corruption.
Why it matters
CVE-2026-44673 is a heap buffer overflow vulnerability in libyang that can cause crashes or potential heap corruption if exploited. Defenders should prioritize patching, restrict untrusted LYB data input, and monitor systems for issues.
- Crash or denial of service in libyang consumers
- Potential heap corruption requiring memory forensics
- Verification of LYB data input validation and sanitization
- Patching libyang to SO 5.2.15 or later for fix
Technical summary
The lyb_read_string() function in src/parser_lyb.c of libyang contains an integer overflow that results in a heap buffer overflow when parsing a maliciously crafted LYB binary blob. This can cause a crash or potential heap corruption if an attacker can supply LYB data to any libyang consumer. The vulnerability is fixed in version SO 5.2.15. Defenders should prioritize patching libyang to version SO 5.2.15 or later, especially in systems where untrusted LYB data is processed. The vulnerability affects libyang consumers such as NETCONF servers and sysrepo.
Defensive priority
Defenders should prioritize patching libyang to version SO 5.2.15 or later, especially in systems where untrusted LYB data is processed.
Recommended defensive actions
- Patch libyang to version SO 5.2.15 or later
- Restrict LYB data input to trusted sources
- Monitor systems for potential crashes or corruption related to libyang
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, its impact, and affected systems. Multiple Red Hat errata references are provided for specific system updates. The vulnerability is confirmed to exist in libyang versions prior to SO 5.2.15. Defenders should verify LYB data input validation and sanitization in their systems. The CVE Program and NVD provide official records and assessments of the vulnerability.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-44673 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-44673
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-44673 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-44673
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/CESNET/libyang/security/advisories/GHSA-vw2p-pq79-92xh
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:24545
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:24758
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:25051
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:49666
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:51339
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:51351
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:51368
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.