CVE-2019-20391: Buffer Overflow
An invalid memory access flaw is present in libyang before v1.0-r3 in the function resolvefeaturevalue() when an if-feature statement is used inside a bit. Applications that use libyang to parse untrusted input yang files may crash.
Other sources
An invalid memory access flaw is present in libyang up to version v1.0-r3 in function resolvefeaturevalue() when a if-feature statement is used inside a bit. Applications that use libyang to parse untrusted input yang files may crash.
Upstream fix: https://github.com/CESNET/libyang/commit/bdb596ddc07596fa212f231135b87d0b9178f6f8
Upstream issue: https://github.com/CESNET/libyang/issues/772
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2019-20391?
CVE-2019-20391 has a moderate severity level due to the potential for application crashes when processing untrusted yang files.
How do I fix CVE-2019-20391?
To fix CVE-2019-20391, upgrade libyang to version 1.0-r3 or later.
What versions of libyang are affected by CVE-2019-20391?
CVE-2019-20391 affects libyang versions up to 1.0-r2, including earlier versions.
What type of applications are impacted by CVE-2019-20391?
Applications that use libyang to parse untrusted input yang files are impacted by CVE-2019-20391.
Is there a risk of data breach with CVE-2019-20391?
While CVE-2019-20391 primarily causes application crashes, using vulnerable versions poses a risk when handling untrusted input.