CVE-2019-20392

MEDIUM

libyang < 1.0-r1 - Denial of Service via Invalid Memory Access in resolve_feature_value()

Title source: llm
STIX 2.1

Description

An invalid memory access flaw is present in libyang before v1.0-r1 in the function resolve_feature_value() when an if-feature statement is used inside a list key node, and the feature used is not defined. Applications that use libyang to parse untrusted input yang files may crash.

Scores

CVSS v3 6.5
EPSS 0.0186
EPSS Percentile 76.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Details

CWE
CWE-119
Status published
Products (6)
cesnet/libyang 0.11 r1 (2 CPE variants)
cesnet/libyang 0.12 r1 (2 CPE variants)
cesnet/libyang 0.13 r1 (2 CPE variants)
cesnet/libyang 0.14 r1
cesnet/libyang 0.15 r1
cesnet/libyang 0.16 r1 (3 CPE variants)
Published Jan 22, 2020
Tracked Since Feb 18, 2026