Libyang Vulnerability in CESNET Product Leading to Crashes
CVE-2021-28906
7.5HIGH
What is CVE-2021-28906?
The libyang library, specifically in versions up to and including v1.0.225, contains a flaw in the read_yin_leaf() function that fails to validate if retval->ext[r] is NULL. This oversight can lead to a dereference of a NULL pointer, causing the application to crash unexpectedly. Developers using this software library should consider applying patches or updates to mitigate potential disruptions in their applications.
