CVE-2021-28902: High severity cesnet vulnerability
Published May 20, 2021
·Updated
In function readyincontainer() in libyang <= v1.0.225, it doesn't check whether the value of retval->ext[r] is NULL. In some cases, it can be NULL, which leads to the operation of retval->ext[r]->flags that results in a crash.
Affected Software
1 affected component
CESNET libyang<=1.0.225
Event History
May 20, 2021
CVE Published
via MITRE·06:36 PM
Data Sourced
via MITRE·06:36 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-28902?
CVE-2021-28902 has been rated as a high severity vulnerability due to potential crashes in affected systems.
2
How do I fix CVE-2021-28902?
To fix CVE-2021-28902, update your libyang library to version 1.0.226 or later.
3
What systems are affected by CVE-2021-28902?
CVE-2021-28902 affects libyang versions up to and including 1.0.225.
4
What are the consequences of exploiting CVE-2021-28902?
Exploiting CVE-2021-28902 can lead to application crashes potentially causing denial of service.
5
Is there a workaround for CVE-2021-28902?
Currently, there is no established workaround for CVE-2021-28902, updating the software is the recommended approach.