CVE-2021-28903: High severity cesnet vulnerability
Published May 20, 2021
·Updated
A stack overflow in libyang <= v1.0.225 can cause a denial of service through function lyxmlparsemem(). lyxmlparseelem() function will be called recursively, which will consume stack space and lead to crash.
Affected Software
1 affected component
CESNET libyang<=1.0.225
Event History
May 20, 2021
CVE Published
via MITRE·06:36 PM
Data Sourced
via MITRE·06:36 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-28903?
CVE-2021-28903 has been classified as a high severity vulnerability due to its potential to cause denial of service.
2
How do I fix CVE-2021-28903?
To fix CVE-2021-28903, upgrade libyang to a version greater than 1.0.225.
3
What impact does CVE-2021-28903 have on systems using libyang?
CVE-2021-28903 can lead to a denial of service by crashing applications that depend on libyang due to a stack overflow.
4
Is CVE-2021-28903 exploitable remotely?
Yes, CVE-2021-28903 can be exploited remotely if the vulnerable libyang library is used in a network-facing application.
5
What versions of libyang are affected by CVE-2021-28903?
CVE-2021-28903 affects all versions of libyang up to and including 1.0.225.