Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:65467 - Security Advisory
Issued:
2026-09-08
Updated:
2026-09-08

RHSA-2026:65467 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: libyang security, bug fix, and enhancement update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for libyang is now available for Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Libyang is YANG data modeling language parser and toolkit written (and providing API) in C.

Security Fix(es):

  • libyang: libyang: Denial of Service or arbitrary code execution via maliciously crafted LYB binary blob (CVE-2026-44673)

Bug Fix(es) and Enhancement(s):

  • Rebase libyang to version 2.1.148 to support FRR in FDP [rhel-9.4.z] (JIRA:RHEL-224576)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server - AUS 9.4 x86_64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.4 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4 x86_64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.4 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.4 s390x
  • Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.4 x86_64
  • Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.4 aarch64
  • Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.4 ppc64le
  • Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.4 s390x

Fixes

  • BZ - 2477617 - CVE-2026-44673 libyang: libyang: Denial of Service or arbitrary code execution via maliciously crafted LYB binary blob
  • RHEL-224576 - Rebase libyang to version 2.1.148 to support FRR in FDP [rhel-9.4.z]

CVEs

  • CVE-2026-44673

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server - AUS 9.4

SRPM
libyang-2.1.148-1.el9_4.1.src.rpm SHA-256: b1e1f5b3d2edda65a2470edba4ac520e1492dffd680e77829fcb12ffcb798fab
x86_64
libyang-2.1.148-1.el9_4.1.i686.rpm SHA-256: 41efb145927db40ca8cfc2c7a592aba336fefe177e291d616e683209759a8d3f
libyang-2.1.148-1.el9_4.1.x86_64.rpm SHA-256: 509cadd2e41bb7fa1949fb6fb3cf4d7f0742cd81334294fa2af6620a790f169c
libyang-debuginfo-2.1.148-1.el9_4.1.i686.rpm SHA-256: 7546f2dc8392e27e8414ad56827aadf65932429f71a96aedcee45a04f4538705
libyang-debuginfo-2.1.148-1.el9_4.1.x86_64.rpm SHA-256: 5f0e9edc282ea766502a2cdc4db363aee83f77fab5e409bd56eae2f406e1e67c
libyang-debugsource-2.1.148-1.el9_4.1.i686.rpm SHA-256: c5ee5d65b8823f0c44fa6c6151945a0c3faa31b14160c86841678a3048ea8d32
libyang-debugsource-2.1.148-1.el9_4.1.x86_64.rpm SHA-256: 4f265ec5c9a8ce80c982109544e92a6c81df93cfa1c084a8f179f96d374a0e30

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.4

SRPM
libyang-2.1.148-1.el9_4.1.src.rpm SHA-256: b1e1f5b3d2edda65a2470edba4ac520e1492dffd680e77829fcb12ffcb798fab
ppc64le
libyang-2.1.148-1.el9_4.1.ppc64le.rpm SHA-256: e5af179035051bf577ddb5ca391fe7d57e3a1abce8baa2875c1ba3fb6a0e9c44
libyang-debuginfo-2.1.148-1.el9_4.1.ppc64le.rpm SHA-256: f3f1301ac4b7020483ea691b5902d10de5aa54a4d76dfa591595b4106ff40b3f
libyang-debugsource-2.1.148-1.el9_4.1.ppc64le.rpm SHA-256: 9de7ab7a4e70eb712c2046bc74111be1596e695a222854627fe8fe5bc31770d6

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4

SRPM
libyang-2.1.148-1.el9_4.1.src.rpm SHA-256: b1e1f5b3d2edda65a2470edba4ac520e1492dffd680e77829fcb12ffcb798fab
x86_64
libyang-2.1.148-1.el9_4.1.i686.rpm SHA-256: 41efb145927db40ca8cfc2c7a592aba336fefe177e291d616e683209759a8d3f
libyang-2.1.148-1.el9_4.1.x86_64.rpm SHA-256: 509cadd2e41bb7fa1949fb6fb3cf4d7f0742cd81334294fa2af6620a790f169c
libyang-debuginfo-2.1.148-1.el9_4.1.i686.rpm SHA-256: 7546f2dc8392e27e8414ad56827aadf65932429f71a96aedcee45a04f4538705
libyang-debuginfo-2.1.148-1.el9_4.1.x86_64.rpm SHA-256: 5f0e9edc282ea766502a2cdc4db363aee83f77fab5e409bd56eae2f406e1e67c
libyang-debugsource-2.1.148-1.el9_4.1.i686.rpm SHA-256: c5ee5d65b8823f0c44fa6c6151945a0c3faa31b14160c86841678a3048ea8d32
libyang-debugsource-2.1.148-1.el9_4.1.x86_64.rpm SHA-256: 4f265ec5c9a8ce80c982109544e92a6c81df93cfa1c084a8f179f96d374a0e30

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.4

SRPM
libyang-2.1.148-1.el9_4.1.src.rpm SHA-256: b1e1f5b3d2edda65a2470edba4ac520e1492dffd680e77829fcb12ffcb798fab
aarch64
libyang-2.1.148-1.el9_4.1.aarch64.rpm SHA-256: be0d8f20db7d197e8efe6f0a3168d0fad36d7c17d4c54a0795ff415f6f0c9cc7
libyang-debuginfo-2.1.148-1.el9_4.1.aarch64.rpm SHA-256: ff8fb1090e80c24b32d081f80e403571436c0c8df76ea568ef83c7468e59e7e8
libyang-debugsource-2.1.148-1.el9_4.1.aarch64.rpm SHA-256: 16af5c35e80195760fe2477e751e1171d98cf798e872540bab94ef7ac5d773b8

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.4

SRPM
libyang-2.1.148-1.el9_4.1.src.rpm SHA-256: b1e1f5b3d2edda65a2470edba4ac520e1492dffd680e77829fcb12ffcb798fab
s390x
libyang-2.1.148-1.el9_4.1.s390x.rpm SHA-256: 4a529a71fec82850ac85af7212f09ae3894be4cdcbea15e18e464f2ea54addb8
libyang-debuginfo-2.1.148-1.el9_4.1.s390x.rpm SHA-256: a6c67bfc85d5698d264475dff1aeb2697236c3e7f71bd8a19b120ea1e9246f88
libyang-debugsource-2.1.148-1.el9_4.1.s390x.rpm SHA-256: 5f98cb1ba65cf5f5d5aeb190a6ec3d4ddc9a930f11a2ec600958afa2356e09a3

Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.4

SRPM
libyang-2.1.148-1.el9_4.1.src.rpm SHA-256: b1e1f5b3d2edda65a2470edba4ac520e1492dffd680e77829fcb12ffcb798fab
x86_64
libyang-2.1.148-1.el9_4.1.i686.rpm SHA-256: 41efb145927db40ca8cfc2c7a592aba336fefe177e291d616e683209759a8d3f
libyang-2.1.148-1.el9_4.1.x86_64.rpm SHA-256: 509cadd2e41bb7fa1949fb6fb3cf4d7f0742cd81334294fa2af6620a790f169c
libyang-debuginfo-2.1.148-1.el9_4.1.i686.rpm SHA-256: 7546f2dc8392e27e8414ad56827aadf65932429f71a96aedcee45a04f4538705
libyang-debuginfo-2.1.148-1.el9_4.1.x86_64.rpm SHA-256: 5f0e9edc282ea766502a2cdc4db363aee83f77fab5e409bd56eae2f406e1e67c
libyang-debugsource-2.1.148-1.el9_4.1.i686.rpm SHA-256: c5ee5d65b8823f0c44fa6c6151945a0c3faa31b14160c86841678a3048ea8d32
libyang-debugsource-2.1.148-1.el9_4.1.x86_64.rpm SHA-256: 4f265ec5c9a8ce80c982109544e92a6c81df93cfa1c084a8f179f96d374a0e30

Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.4

SRPM
libyang-2.1.148-1.el9_4.1.src.rpm SHA-256: b1e1f5b3d2edda65a2470edba4ac520e1492dffd680e77829fcb12ffcb798fab
aarch64
libyang-2.1.148-1.el9_4.1.aarch64.rpm SHA-256: be0d8f20db7d197e8efe6f0a3168d0fad36d7c17d4c54a0795ff415f6f0c9cc7
libyang-debuginfo-2.1.148-1.el9_4.1.aarch64.rpm SHA-256: ff8fb1090e80c24b32d081f80e403571436c0c8df76ea568ef83c7468e59e7e8
libyang-debugsource-2.1.148-1.el9_4.1.aarch64.rpm SHA-256: 16af5c35e80195760fe2477e751e1171d98cf798e872540bab94ef7ac5d773b8

Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.4

SRPM
libyang-2.1.148-1.el9_4.1.src.rpm SHA-256: b1e1f5b3d2edda65a2470edba4ac520e1492dffd680e77829fcb12ffcb798fab
ppc64le
libyang-2.1.148-1.el9_4.1.ppc64le.rpm SHA-256: e5af179035051bf577ddb5ca391fe7d57e3a1abce8baa2875c1ba3fb6a0e9c44
libyang-debuginfo-2.1.148-1.el9_4.1.ppc64le.rpm SHA-256: f3f1301ac4b7020483ea691b5902d10de5aa54a4d76dfa591595b4106ff40b3f
libyang-debugsource-2.1.148-1.el9_4.1.ppc64le.rpm SHA-256: 9de7ab7a4e70eb712c2046bc74111be1596e695a222854627fe8fe5bc31770d6

Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.4

SRPM
libyang-2.1.148-1.el9_4.1.src.rpm SHA-256: b1e1f5b3d2edda65a2470edba4ac520e1492dffd680e77829fcb12ffcb798fab
s390x
libyang-2.1.148-1.el9_4.1.s390x.rpm SHA-256: 4a529a71fec82850ac85af7212f09ae3894be4cdcbea15e18e464f2ea54addb8
libyang-debuginfo-2.1.148-1.el9_4.1.s390x.rpm SHA-256: a6c67bfc85d5698d264475dff1aeb2697236c3e7f71bd8a19b120ea1e9246f88
libyang-debugsource-2.1.148-1.el9_4.1.s390x.rpm SHA-256: 5f98cb1ba65cf5f5d5aeb190a6ec3d4ddc9a930f11a2ec600958afa2356e09a3

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility