PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-44673 CESNET CVE debrief

libyang is vulnerable to a heap buffer overflow when parsing maliciously crafted LYB binary blobs. This issue, fixed in version SO 5.2.15, can lead to a crash or potential heap corruption if an attacker supplies LYB data to any libyang consumer. The vulnerability is caused by an integer overflow in the lyb_read_string() function in src/parser_lyb.c. Defenders managing systems that use libyang, especially those processing untrusted LYB data, should assess exposure and prioritize patching to prevent potential crashes or heap corruption.

Vendor
CESNET
Product
libyang
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-14
Original CVE updated
2026-09-09
Advisory published
2026-05-14
Advisory updated
2026-09-09

Who should care

Defenders managing systems that use libyang, especially those processing untrusted LYB data, should assess exposure and prioritize patching to prevent potential crashes or heap corruption.

Why it matters

CVE-2026-44673 is a heap buffer overflow vulnerability in libyang that can cause crashes or potential heap corruption if exploited. Defenders should prioritize patching, restrict untrusted LYB data input, and monitor systems for issues.

  • Crash or denial of service in libyang consumers
  • Potential heap corruption requiring memory forensics
  • Verification of LYB data input validation and sanitization
  • Patching libyang to SO 5.2.15 or later for fix

Technical summary

The lyb_read_string() function in src/parser_lyb.c of libyang contains an integer overflow that results in a heap buffer overflow when parsing a maliciously crafted LYB binary blob. This can cause a crash or potential heap corruption if an attacker can supply LYB data to any libyang consumer. The vulnerability is fixed in version SO 5.2.15. Defenders should prioritize patching libyang to version SO 5.2.15 or later, especially in systems where untrusted LYB data is processed. The vulnerability affects libyang consumers such as NETCONF servers and sysrepo.

Defensive priority

Defenders should prioritize patching libyang to version SO 5.2.15 or later, especially in systems where untrusted LYB data is processed.

Recommended defensive actions

  • Patch libyang to version SO 5.2.15 or later
  • Restrict LYB data input to trusted sources
  • Monitor systems for potential crashes or corruption related to libyang
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, its impact, and affected systems. Multiple Red Hat errata references are provided for specific system updates. The vulnerability is confirmed to exist in libyang versions prior to SO 5.2.15. Defenders should verify LYB data input validation and sanitization in their systems. The CVE Program and NVD provide official records and assessments of the vulnerability.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-44673 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-44673

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-44673 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-44673

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://github.com/CESNET/libyang/security/advisories/GHSA-vw2p-pq79-92xh

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:24545

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:24758

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:25051

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:49666

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:51339

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:51351

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:51368

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.