5.3
CVSSv3

CVE-2023-26916

Published: 03/04/2023 Updated: 07/11/2023
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

libyang from v2.0.164 to v2.1.30 exists to contain a NULL pointer dereference via the function lys_parse_mem at lys_parse_mem.c.

Vulnerable Product Search on Vulmon Subscribe to Product

cesnet libyang

fedoraproject fedora 36

fedoraproject fedora 37

Vendor Advisories

Debian Bug report logs - #1034154 libyang2: CVE-2023-26916 Package: src:libyang2; Maintainer for src:libyang2 is Ondřej Surý <ondrej@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 10 Apr 2023 12:36:01 UTC Severity: important Tags: security, upstream Found in version libyang2/2130-2 ...
DescriptionThe MITRE CVE dictionary describes this issue as: libyang from v20164 to v2130 was discovered to contain a NULL pointer dereference via the function lys_parse_mem at lys_parse_memc ...