{"id":"AZL-86816","summary":"CVE-2026-44673 affecting package libyang for versions less than 2.1.148-3","details":"libyang is a YANG data modeling language library. Prior to SO 5.2.15, lyb_read_string() in src/parser_lyb.c contains an integer overflow that results in a heap buffer overflow when parsing a maliciously crafted LYB binary blob. An attacker who can supply LYB data to any libyang consumer (NETCONF server, sysrepo, etc.) can trigger a crash or potential heap corruption. This vulnerability is fixed in SO 5.2.15.","modified":"2026-09-20T05:33:47Z","published":"2026-05-14T21:16:47Z","upstream":["CVE-2026-44673"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44673"}],"affected":[{"package":{"name":"libyang","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/libyang"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.1.148-3"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-86816.json"}}],"schema_version":"1.9.0"}