Hi,
The following vulnerability was published for libyang.
CVE-2026-41401[0]:
| libyang before 5.2.6 contains a heap use-after-free write
| vulnerability in lyd_parser_set_data_flags that incorrectly updates
| metadata list pointers when freeing non-head default metadata
| entries. Attackers can trigger this vulnerability by submitting
| crafted YANG XML documents with specific metadata attributes to
| applications parsing untrusted XML data, causing process crashes or
| potential code execution.
https://github.com/CESNET/libyang/security/advisories/GHSA-9f49-8x56-jmjc
Fixed by: https://github.com/CESNET/libyang/commit/54c3276d871023da266d4ed3ceaee7e8d71d0b04 (v5.4.9)
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-41401
https://www.cve.org/CVERecord?id=CVE-2026-41401
Please adjust the affected versions in the BTS as needed.