First published: Tue Apr 11 2023(Updated: )
libyang from v2.0.164 to v2.1.30 was discovered to contain a NULL pointer dereference via the function lysp_stmt_validate_value at lys_parse_mem.c.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CESNET libyang | >=2.0.164<=2.1.30 | |
>=2.0.164<=2.1.30 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-26917 has been classified as a medium severity vulnerability due to its potential for causing application crashes.
To remediate CVE-2023-26917, update libyang to version 2.1.31 or higher, which resolves the NULL pointer dereference issue.
CVE-2023-26917 affects libyang versions from 2.0.164 to 2.1.30.
Exploiting CVE-2023-26917 can lead to application crashes due to NULL pointer dereference.
There are no recommended workarounds for CVE-2023-26917 other than upgrading to the patched version.