Source: libyang X-Debbugs-CC: [email protected] Severity: important Tags: security
Hi, The following vulnerability was published for libyang. CVE-2026-41401[0]: | libyang before 5.2.6 contains a heap use-after-free write | vulnerability in lyd_parser_set_data_flags that incorrectly updates | metadata list pointers when freeing non-head default metadata | entries. Attackers can trigger this vulnerability by submitting | crafted YANG XML documents with specific metadata attributes to | applications parsing untrusted XML data, causing process crashes or | potential code execution. https://github.com/CESNET/libyang/security/advisories/GHSA-9f49-8x56-jmjc Fixed by: https://github.com/CESNET/libyang/commit/54c3276d871023da266d4ed3ceaee7e8d71d0b04 (v5.4.9) If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-41401 https://www.cve.org/CVERecord?id=CVE-2026-41401 Please adjust the affected versions in the BTS as needed.

