libyang is a YANG data modeling language library. Prior to SO 5.2.15, lyb_read_string() in src/parser_lyb.c contains an integer overflow that results in a heap buffer overflow when parsing a maliciously crafted LYB binary blob. An attacker who can supply LYB data to any libyang consumer (NETCONF server, sysrepo, etc.) can trigger a crash or potential heap corruption. This vulnerability is fixed in SO 5.2.15.
History

Sat, 16 May 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Fri, 15 May 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 14 May 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Cesnet
Cesnet libyang
Vendors & Products Cesnet
Cesnet libyang

Thu, 14 May 2026 20:45:00 +0000

Type Values Removed Values Added
Description libyang is a YANG data modeling language library. Prior to SO 5.2.15, lyb_read_string() in src/parser_lyb.c contains an integer overflow that results in a heap buffer overflow when parsing a maliciously crafted LYB binary blob. An attacker who can supply LYB data to any libyang consumer (NETCONF server, sysrepo, etc.) can trigger a crash or potential heap corruption. This vulnerability is fixed in SO 5.2.15.
Title libyang: lyb_read_string() integer overflow → heap buffer overflow
Weaknesses CWE-190
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-05-15T14:19:01.227Z

Reserved: 2026-05-07T16:20:08.659Z

Link: CVE-2026-44673

cve-icon Vulnrichment

Updated: 2026-05-15T14:18:56.857Z

cve-icon NVD

Status : Deferred

Published: 2026-05-14T21:16:47.500

Modified: 2026-05-15T15:16:53.830

Link: CVE-2026-44673

cve-icon Redhat

Severity : Important

Publid Date: 2026-05-14T20:35:13Z

Links: CVE-2026-44673 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-05-14T21:30:12Z