PatchSiren

CESNET CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH CESNET CVE published 2026-05-14

CVE-2026-44673

libyang is vulnerable to a heap buffer overflow when parsing maliciously crafted LYB binary blobs. This issue, fixed in version SO 5.2.15, can lead to a crash or potential heap corruption if an attacker supplies LYB data to any libyang consumer. The vulnerability is caused by an integer overflow in the lyb_read_string() function in src/parser_lyb.c. Defenders managing systems that use libyang, especially [truncated]