CVE-2023-26916: Null Pointer Dereference
Published Apr 3, 2023
·Updated
libyang from v2.0.164 to v2.1.30 was discovered to contain a NULL pointer dereference via the function lysparsemem at lysparsemem.c.
Affected Software
3 affected components
CESNET libyang>=2.0.164<=2.1.30
Fedoraproject Fedora=36
Fedoraproject Fedora=37
Event History
Apr 3, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-26916?
CVE-2023-26916 is a vulnerability in libyang from version 2.0.164 to version 2.1.30 that can result in a NULL pointer dereference.
2
How severe is CVE-2023-26916?
CVE-2023-26916 has a severity rating of medium, with a CVSS score of 5.3.
3
What software is affected by CVE-2023-26916?
Cesnet Libyang versions 2.0.164 to 2.1.30, Fedora 36, and Fedora 37 are affected by CVE-2023-26916.
4
What is the CWE ID of CVE-2023-26916?
CVE-2023-26916 is associated with CWE ID 476.
5
How can CVE-2023-26916 be fixed?
To fix CVE-2023-26916, users should update their libyang software to a version that has the patch for the vulnerability.