Search CVE reports


Toggle filters

1 – 5 of 5 results


CVE-2026-41401

Medium priority
Needs evaluation

libyang before 5.2.6 contains a heap use-after-free write vulnerability in lyd_parser_set_data_flags that incorrectly updates metadata list pointers when freeing non-head default metadata entries. Attackers can trigger...

2 affected packages

libyang, libyang2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libyang Needs evaluation Not in release Needs evaluation Needs evaluation
libyang2 Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-44673

Medium priority
Needs evaluation

libyang is a YANG data modeling language library. Prior to SO 5.2.15, lyb_read_string() in src/parser_lyb.c contains an integer overflow that results in a heap buffer overflow when parsing a maliciously crafted LYB binary blob. An...

2 affected packages

libyang, libyang2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libyang Needs evaluation Not in release Needs evaluation Needs evaluation
libyang2 Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2023-26917

Medium priority

Some fixes available 1 of 2

libyang from v2.0.164 to v2.1.30 was discovered to contain a NULL pointer dereference via the function lysp_stmt_validate_value at lys_parse_mem.c.

2 affected packages

libyang, libyang2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libyang Not in release Not affected Not affected Not in release
libyang2 Fixed Not affected
Show less packages

CVE-2023-26916

Medium priority

Some fixes available 1 of 2

libyang from v2.0.164 to v2.1.30 was discovered to contain a NULL pointer dereference via the function lys_parse_mem at lys_parse_mem.c.

2 affected packages

libyang, libyang2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libyang Not in release Not affected Not affected Not in release
libyang2 Fixed Not affected
Show less packages

CVE-2019-20395

Medium priority
Vulnerable

A stack consumption issue is present in libyang before v1.0-r1 due to the self-referential union type containing leafrefs. Applications that use libyang to parse untrusted input yang files may crash.

2 affected packages

libyang, libyang2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libyang Not affected Not in release Not affected Vulnerable Not in release
libyang2 Not in release Not affected Not affected Not in release Not in release
Show less packages