RHSA-2026:49666: Important: libyang security update
Important: libyang security update
Other sources
Libyang is YANG data modeling language parser and toolkit written (and providing API) in C.Security Fix(es): libyang: libyang: Denial of Service or arbitrary code execution via maliciously crafted LYB binary blob (CVE-2026-44673) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/libyangto a version that resolves this vulnerability.Fixed in 2.1.148-2.el10_0.1 - Upgrade
Upgrade
redhat/libyang-debuginfoto a version that resolves this vulnerability.Fixed in 2.1.148-2.el10_0.1 - Upgrade
Upgrade
redhat/libyang-debugsourceto a version that resolves this vulnerability.Fixed in 2.1.148-2.el10_0.1 - Upgrade
Upgrade
redhat/libyang-tools-debuginfoto a version that resolves this vulnerability.Fixed in 2.1.148-2.el10_0.1 - Upgrade
Upgrade
redhat/libyangto a version that resolves this vulnerability.Fixed in 2.1.148-2.el10_0.1.aa - Upgrade
Upgrade
redhat/libyang-debuginfoto a version that resolves this vulnerability.Fixed in 2.1.148-2.el10_0.1.aa - Upgrade
Upgrade
redhat/libyang-debugsourceto a version that resolves this vulnerability.Fixed in 2.1.148-2.el10_0.1.aa - Upgrade
Upgrade
redhat/libyang-tools-debuginfoto a version that resolves this vulnerability.Fixed in 2.1.148-2.el10_0.1.aa
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:49666?
The severity of RHSA-2026:49666 is rated as high, with a score of 7.
What vulnerabilities are addressed in RHSA-2026:49666?
RHSA-2026:49666 addresses a denial of service or arbitrary code execution vulnerability via maliciously crafted LYB binary blob (CVE-2026-44673).
How do I fix RHSA-2026:49666?
To fix RHSA-2026:49666, update your libyang packages to the latest version provided by Red Hat.
Which software packages are affected by RHSA-2026:49666?
The affected packages include redhat/libyang, redhat/libyang-debuginfo, redhat/libyang-debugsource, and redhat/libyang-tools-debuginfo.
What is libyang in the context of RHSA-2026:49666?
Libyang is a YANG data modeling language parser and toolkit written in C, which is impacted by the security update described in RHSA-2026:49666.