CVE-2026-44673: CWE-190: Integer Overflow or Wraparound in CESNET libyang
libyang is a YANG data modeling language library. Prior to SO 5.2.15, lyb_read_string() in src/parser_lyb.c contains an integer overflow that results in a heap buffer overflow when parsing a maliciously crafted LYB binary blob. An attacker who can supply LYB data to any libyang consumer (NETCONF server, sysrepo, etc.) can trigger a crash or potential heap corruption. This vulnerability is fixed in SO 5.2.15.
AI Analysis
Technical Summary
CVE-2026-44673 is an integer overflow vulnerability in the lyb_read_string() function of libyang, which can cause a heap buffer overflow when parsing malicious LYB binary blobs. This flaw can be exploited remotely by providing crafted LYB data to libyang consumers, potentially causing a denial of service via crash or enabling arbitrary code execution through heap corruption. The vulnerability impacts Red Hat Enterprise Linux and related products that use libyang, such as NETCONF servers. Red Hat has issued security advisories and released updated libyang packages to fix this issue.
Potential Impact
The vulnerability allows remote attackers to cause denial of service by crashing affected applications or potentially execute arbitrary code due to heap corruption. This can disrupt services relying on libyang, such as NETCONF servers, impacting availability and potentially compromising system integrity.
Mitigation Recommendations
Red Hat has released updated libyang packages that fix this vulnerability. Users should apply the security updates provided by Red Hat for affected products, including Red Hat Enterprise Linux 10 and related CodeReady Linux Builder versions. No effective mitigations other than applying the official patches are available or meet Red Hat's criteria. Refer to Red Hat advisory RHSA-2026:24758 for update instructions.
CVE-2026-44673: CWE-190: Integer Overflow or Wraparound in CESNET libyang
Description
libyang is a YANG data modeling language library. Prior to SO 5.2.15, lyb_read_string() in src/parser_lyb.c contains an integer overflow that results in a heap buffer overflow when parsing a maliciously crafted LYB binary blob. An attacker who can supply LYB data to any libyang consumer (NETCONF server, sysrepo, etc.) can trigger a crash or potential heap corruption. This vulnerability is fixed in SO 5.2.15.
CVSS v3.1
Score 7.5high
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-44673 is an integer overflow vulnerability in the lyb_read_string() function of libyang, which can cause a heap buffer overflow when parsing malicious LYB binary blobs. This flaw can be exploited remotely by providing crafted LYB data to libyang consumers, potentially causing a denial of service via crash or enabling arbitrary code execution through heap corruption. The vulnerability impacts Red Hat Enterprise Linux and related products that use libyang, such as NETCONF servers. Red Hat has issued security advisories and released updated libyang packages to fix this issue.
Potential Impact
The vulnerability allows remote attackers to cause denial of service by crashing affected applications or potentially execute arbitrary code due to heap corruption. This can disrupt services relying on libyang, such as NETCONF servers, impacting availability and potentially compromising system integrity.
Mitigation Recommendations
Red Hat has released updated libyang packages that fix this vulnerability. Users should apply the security updates provided by Red Hat for affected products, including Red Hat Enterprise Linux 10 and related CodeReady Linux Builder versions. No effective mitigations other than applying the official patches are available or meet Red Hat's criteria. Refer to Red Hat advisory RHSA-2026:24758 for update instructions.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:24545
- Cve Count
- 1
- State
- PUBLISHED
Threat ID: 6a27320be29bf47b509bea64
Added to database: 06/08/2026, 21:20:11 UTC
Last enriched: 08/03/2026, 22:33:28 UTC
Last updated: 09/14/2026, 22:01:34 UTC
Views: 120
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.