gpp_maybe Security update for libyang
SUSE-SLE-Module-Server-Applications-15-SP7-2026-2337


This update for libyang fixes the following issues - CVE-2026-41401: use-after-free in `lyd_parser_set_data_flags` when processing crafted YANG XML documents with specific metadata attributes (bsc#1266316). - CVE-2026-44673: integer overflow in `lyb_read_string()` of `src/parser_lyb.c` leads to heap buffer overflow when parsing a maliciously crafted LYB binary blob (bsc#1265330).


cloud_download Downloads

Server Applications Module 15.7 aarch64
  • Packages
    libyang
    Parser toolkit for IETF YANG data modeling
    2.1.148-150700.3.5.1 lock src
    libyang2
    IETF YANG data modeling parser toolkit runtime
    2.1.148-150700.3.5.1 lock rpm
Server Applications Module 15.7 ppc64le
  • Packages
    libyang
    Parser toolkit for IETF YANG data modeling
    2.1.148-150700.3.5.1 lock src
    libyang2
    IETF YANG data modeling parser toolkit runtime
    2.1.148-150700.3.5.1 lock rpm
Server Applications Module 15.7 s390x
  • Packages
    libyang
    Parser toolkit for IETF YANG data modeling
    2.1.148-150700.3.5.1 lock src
    libyang2
    IETF YANG data modeling parser toolkit runtime
    2.1.148-150700.3.5.1 lock rpm
Server Applications Module 15.7 x86_64
  • Packages
    libyang
    Parser toolkit for IETF YANG data modeling
    2.1.148-150700.3.5.1 lock src
    libyang2
    IETF YANG data modeling parser toolkit runtime
    2.1.148-150700.3.5.1 lock rpm