Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-87354.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-87354
Upstream
Published
2026-05-26T15:16:35Z
Modified
2026-08-30T05:26:50Z
Summary
CVE-2026-41401 affecting package libyang for versions less than 2.1.148-3
Details

libyang before 5.2.6 contains a heap use-after-free write vulnerability in lydparsersetdataflags that incorrectly updates metadata list pointers when freeing non-head default metadata entries. Attackers can trigger this vulnerability by submitting crafted YANG XML documents with specific metadata attributes to applications parsing untrusted XML data, causing process crashes or potential code execution.

References

Affected packages

Azure Linux:3 / libyang

Package

Name
libyang
Purl
pkg:rpm/azure-linux/libyang

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.1.148-3

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-87354.json"