CVE-2019-20392

MEDIUM

Cesnet Libyang - Memory Corruption

Title source: rule
STIX 2.1

Description

An invalid memory access flaw is present in libyang before v1.0-r1 in the function resolve_feature_value() when an if-feature statement is used inside a list key node, and the feature used is not defined. Applications that use libyang to parse untrusted input yang files may crash.

Scores

CVSS v3 6.5
EPSS 0.0020
EPSS Percentile 42.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Details

CWE
CWE-119
Status published
Products (6)
cesnet/libyang 0.11 r1 (2 CPE variants)
cesnet/libyang 0.12 r1 (2 CPE variants)
cesnet/libyang 0.13 r1 (2 CPE variants)
cesnet/libyang 0.14 r1
cesnet/libyang 0.15 r1
cesnet/libyang 0.16 r1 (3 CPE variants)
Published Jan 22, 2020
Tracked Since Feb 18, 2026