RHSA-2026:49666: Important: libyang security update
Important: libyang security update
Other sources
Libyang is YANG data modeling language parser and toolkit written (and providing API) in C.Security Fix(es): libyang: libyang: Denial of Service or arbitrary code execution via maliciously crafted LYB binary blob (CVE-2026-44673) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/libyangto a version that resolves this vulnerability.Fixed in 2.1.148-2.el10_0.1 - Upgrade
Upgrade
redhat/libyang-debuginfoto a version that resolves this vulnerability.Fixed in 2.1.148-2.el10_0.1 - Upgrade
Upgrade
redhat/libyang-debugsourceto a version that resolves this vulnerability.Fixed in 2.1.148-2.el10_0.1 - Upgrade
Upgrade
redhat/libyang-tools-debuginfoto a version that resolves this vulnerability.Fixed in 2.1.148-2.el10_0.1 - Upgrade
Upgrade
redhat/libyangto a version that resolves this vulnerability.Fixed in 2.1.148-2.el10_0.1.aa - Upgrade
Upgrade
redhat/libyang-debuginfoto a version that resolves this vulnerability.Fixed in 2.1.148-2.el10_0.1.aa - Upgrade
Upgrade
redhat/libyang-debugsourceto a version that resolves this vulnerability.Fixed in 2.1.148-2.el10_0.1.aa - Upgrade
Upgrade
redhat/libyang-tools-debuginfoto a version that resolves this vulnerability.Fixed in 2.1.148-2.el10_0.1.aa