---
title: "CVE-2026-41401\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2026-41401?format=md
keywords: index, follow
---

# CVE-2026-41401

Publication date 26 May 2026

Last updated 30 June 2026

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**6.5 · Medium**

[Score breakdown](https://ubuntu.com/security/CVE-2026-41401?format=md#impact-score)

Toggle side navigation

## Description

libyang before 5.2.6 contains a heap use-after-free write vulnerability in
lyd\_parser\_set\_data\_flags that incorrectly updates metadata list pointers
when freeing non-head default metadata entries. Attackers can trigger this
vulnerability by submitting crafted YANG XML documents with specific
metadata attributes to applications parsing untrusted XML data, causing
process crashes or potential code execution.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2026-41401?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| libyang | 26.04 LTS resolute | Fixed 3.13.6-1ubuntu0.1 |
| 25.10 questing | Fixed 3.13.5-2ubuntu0.1 |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Needs evaluation |
| 20.04 LTS focal | Needs evaluation |
| libyang2 | 26.04 LTS resolute | Not in release |
| 25.10 questing | Not in release |
| 24.04 LTS noble | Not affected |
| 22.04 LTS jammy | Not affected |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2026-41401?format=md#patch-details)

## Notes

---

### [mdeslaur](https://launchpad.net/~mdeslaur)

This vulnerability was introduced in 2.2.8 by:
https://github.com/CESNET/libyang/commit/ed39cbead79d8b2beb0aa5ffcea874677a17ea4a

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| libyang | * Upstream:   [54c3276](https://github.com/CESNET/libyang/commit/54c3276d871023da266d4ed3ceaee7e8d71d0b04) |

## Severity score breakdown

CVSS version:

CVSS v4.0

[CVSS v4.0](https://ubuntu.com/security/CVE-2026-41401?format=md)
[CVSS v3.0](https://ubuntu.com/security/CVE-2026-41401?format=md)

**Base score**

7.1 · High

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Attack requirements | None |
  | Privileges required | Low |
  | User interaction | None |
  | Vulnerable system - Confidentiality impact | None |
  | Vulnerable system - Integrity impact | None |
  | Vulnerable system - Availability impact | High |
  | Subsequent system - Confidentiality impact | None |
  | Subsequent system - Integrity impact | None |
  | Subsequent system - Availability impact | None |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 7.1 · High |
  | Base + Threat score | - |
  | Base + Environmental score | - |
  | Base + Threat + Environmental score | - |

**Vector:** CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-41401)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2026-41401)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2026-41401)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2026-41401)

### Related Ubuntu Security Notices (USN)

+ [USN-8485-1](https://usn.ubuntu.com/USN-8485-1)
+ libyang vulnerability
+ 30 June 2026

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2026-41401>
* <https://github.com/CESNET/libyang/commit/6b5ed47ee674fbe86b31bbebc4ff26889aeff38c>
* <https://github.com/CESNET/libyang/security/advisories/GHSA-9f49-8x56-jmjc>
* <https://red.anthropic.com/2026/cvd/findings/ANT-2026-TZQ1KH7E>
* <https://www.vulncheck.com/advisories/libyang-heap-use-after-free-write-in-xml-metadata-parsing>
