Source: libyang
X-Debbugs-CC: [email protected]
Severity: important
Tags: security

Hi,

The following vulnerability was published for libyang.

CVE-2026-41401[0]:
| libyang before 5.2.6 contains a heap use-after-free write
| vulnerability in lyd_parser_set_data_flags that incorrectly updates
| metadata list pointers when freeing non-head default metadata
| entries. Attackers can trigger this vulnerability by submitting
| crafted YANG XML documents with specific metadata attributes to
| applications parsing untrusted XML data, causing process crashes or
| potential code execution.

https://github.com/CESNET/libyang/security/advisories/GHSA-9f49-8x56-jmjc
Fixed by: 
https://github.com/CESNET/libyang/commit/54c3276d871023da266d4ed3ceaee7e8d71d0b04
 (v5.4.9)


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-41401
    https://www.cve.org/CVERecord?id=CVE-2026-41401

Please adjust the affected versions in the BTS as needed.

Reply via email to