#1149179 libyang: CVE-2026-41401

Package:
src:libyang
Source:
src:libyang
Submitter:
Moritz Mühlenhoff
Date:
2026-09-28 03:37:01 UTC
Severity:
normal
Tags:
#1149179#5
Date:
2026-09-27 20:48:04 UTC
From:
To:
Hi,

The following vulnerability was published for libyang.

CVE-2026-41401[0]:
| libyang before 5.2.6 contains a heap use-after-free write
| vulnerability in lyd_parser_set_data_flags that incorrectly updates
| metadata list pointers when freeing non-head default metadata
| entries. Attackers can trigger this vulnerability by submitting
| crafted YANG XML documents with specific metadata attributes to
| applications parsing untrusted XML data, causing process crashes or
| potential code execution.

https://github.com/CESNET/libyang/security/advisories/GHSA-9f49-8x56-jmjc
Fixed by: https://github.com/CESNET/libyang/commit/54c3276d871023da266d4ed3ceaee7e8d71d0b04 (v5.4.9)


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-41401
https://www.cve.org/CVERecord?id=CVE-2026-41401

Please adjust the affected versions in the BTS as needed.