The libyang package provides a library for YANG data modeling language. libyang is a YANG data modelling language parser and toolkit written (and providing API) in C. The library is used e.g. in libnetconf2, Netopeer2, sysrepo and FRRouting projects.
* libyang: stack-based buffer overflow in make_canonical when bits leaf type is used (CVE-2019-19333)
* libyang: stack-based buffer overflow in make_canonical when identityref leaf type is used (CVE-2019-19334)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
The libyang-devel sub-package has recently been removed from the AppStream repository. If you have previously installed libyang-devel, remove it prior to applying this advisory to make the update successful.
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the AlmaLinux Packaging Team