CVE-2023-26917: Null Pointer Dereference
Published Apr 11, 2023
·Updated
libyang from v2.0.164 to v2.1.30 was discovered to contain a NULL pointer dereference via the function lyspstmtvalidatevalue at lysparsemem.c.
Affected Software
1 affected component
CESNET libyang>=2.0.164<=2.1.30
Event History
Apr 11, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-26917?
CVE-2023-26917 has been classified as a medium severity vulnerability due to its potential for causing application crashes.
2
How do I fix CVE-2023-26917?
To remediate CVE-2023-26917, update libyang to version 2.1.31 or higher, which resolves the NULL pointer dereference issue.
3
What versions of libyang are affected by CVE-2023-26917?
CVE-2023-26917 affects libyang versions from 2.0.164 to 2.1.30.
4
What is the impact of exploiting CVE-2023-26917?
Exploiting CVE-2023-26917 can lead to application crashes due to NULL pointer dereference.
5
Is there a workaround for CVE-2023-26917?
There are no recommended workarounds for CVE-2023-26917 other than upgrading to the patched version.