RHSA-2026:51339: Important: libyang security update
Important: libyang security update
Other sources
Libyang is YANG data modeling language parser and toolkit written (and providing API) in C.Security Fix(es): libyang: libyang: Denial of Service or arbitrary code execution via maliciously crafted LYB binary blob (CVE-2026-44673) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/libyangto a version that resolves this vulnerability.Fixed in 1.0.184-1.el8_8.1 - Upgrade
Upgrade
redhat/libyang-cpp-debuginfoto a version that resolves this vulnerability.Fixed in 1.0.184-1.el8_8.1 - Upgrade
Upgrade
redhat/libyang-debuginfoto a version that resolves this vulnerability.Fixed in 1.0.184-1.el8_8.1 - Upgrade
Upgrade
redhat/libyang-debugsourceto a version that resolves this vulnerability.Fixed in 1.0.184-1.el8_8.1 - Upgrade
Upgrade
redhat/python3-libyang-debuginfoto a version that resolves this vulnerability.Fixed in 1.0.184-1.el8_8.1 - Compensating control
Mitigate exposure to CVE-2026-44673 by avoiding processing of untrusted/maliciously crafted LYB binary blobs with libyang until the security update described in the advisory is applied.
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:51339?
The severity of RHSA-2026:51339 is rated high with a score of 7.
How do I fix RHSA-2026:51339?
To fix RHSA-2026:51339, users should update the libyang packages to the latest version provided by Red Hat.
What type of vulnerability is addressed in RHSA-2026:51339?
RHSA-2026:51339 addresses a vulnerability that can lead to Denial of Service or arbitrary code execution via maliciously crafted LYB binary blobs.
What software is affected by RHSA-2026:51339?
The affected software includes various packages of libyang in Red Hat Enterprise Linux, including libyang, libyang-cpp-debuginfo, and python3-libyang-debuginfo.
What is CVE-2026-44673 in relation to RHSA-2026:51339?
CVE-2026-44673 is the specific identifier for the vulnerability that RHSA-2026:51339 addresses, concerning Denial of Service and arbitrary code execution risks.