Libyang Vulnerability in CESNET Product Leading to Crashes
CVE-2021-28906

7.5HIGH

Key Information:

Vendor

Cesnet

Status
Vendor
CVE Published:
20 May 2021

What is CVE-2021-28906?

The libyang library, specifically in versions up to and including v1.0.225, contains a flaw in the read_yin_leaf() function that fails to validate if retval->ext[r] is NULL. This oversight can lead to a dereference of a NULL pointer, causing the application to crash unexpectedly. Developers using this software library should consider applying patches or updates to mitigate potential disruptions in their applications.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.