Back

CRITICAL

libyang: stack-based buffer overflow in make_canonical when bits leaf type is used

Published Dec 6, 2019

Description

In all versions of libyang before 1.0-r5, a stack-based buffer overflow was discovered in the way libyang parses YANG files with a leaf of type "bits". An application that uses libyang to parse untrusted YANG files may be vulnerable to this flaw, which would allow an attacker to cause a denial of service or possibly gain code execution.

Affected products

Remediation

No remediation recorded yet.

References (10)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner redhat
Published Dec 6, 2019
Updated Aug 5, 2024
Reserved Nov 27, 2019

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Important
Public date Dec 5, 2019
Bugzilla 1779573

ENISA EUVD

Assigner redhat
Published Dec 6, 2019
Updated Aug 5, 2024

GitHub

No data