NA

CVE-2023-26917

Published: 11/04/2023 Updated: 18/04/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

libyang from v2.0.164 to v2.1.30 exists to contain a NULL pointer dereference via the function lysp_stmt_validate_value at lys_parse_mem.c.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cesnet libyang

Vendor Advisories

Debian Bug report logs - #1034724 libyang2: CVE-2023-26917 Package: src:libyang2; Maintainer for src:libyang2 is Ondřej Surý <ondrej@debianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Sat, 22 Apr 2023 17:33:09 UTC Severity: important Tags: security, upstream Found in version libyang2/2130-2 F ...
DescriptionThe MITRE CVE dictionary describes this issue as: libyang from v20164 to v2130 was discovered to contain a NULL pointer dereference via the function lysp_stmt_validate_value at lys_parse_memc ...