HIGH
CESNET
CVE published 2026-05-14
CVE-2026-44673
libyang is vulnerable to a heap buffer overflow when parsing maliciously crafted LYB binary blobs. This issue, fixed in version SO 5.2.15, can lead to a crash or potential heap corruption if an attacker supplies LYB data to any libyang consumer. The vulnerability is caused by an integer overflow in the lyb_read_string() function in src/parser_lyb.c. Defenders managing systems that use libyang, especially [truncated]