CVE-2019-20397

HIGH

Cesnet Libyang - Double Free

Title source: rule
STIX 2.1

Description

A double-free is present in libyang before v1.0-r1 in the function yyparse() when an organization field is not terminated. Applications that use libyang to parse untrusted input yang files may be vulnerable to this flaw, which would cause a crash or potentially code execution.

Scores

CVSS v3 8.8
EPSS 0.0040
EPSS Percentile 60.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-415
Status published
Products (6)
cesnet/libyang 0.11 r1 (2 CPE variants)
cesnet/libyang 0.12 r1 (2 CPE variants)
cesnet/libyang 0.13 r1 (2 CPE variants)
cesnet/libyang 0.14 r1
cesnet/libyang 0.15 r1
cesnet/libyang 0.16 r1 (3 CPE variants)
Published Jan 22, 2020
Tracked Since Feb 18, 2026