Back to Database
Status published
Medium
CVE-2019-20395
A stack consumption issue is present in libyang before v1.0-r1...
Vulnerability Description
A stack consumption issue is present in libyang before v1.0-r1 due to the self-referential union type containing leafrefs. Applications that use libyang to parse untrusted input yang files may crash.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-20395
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/CESNET/libyang/compare/v0.16-r3...v1.0-r1
- https://github.com/CESNET/libyang/issues/724
- https://github.com/CESNET/libyang/commit/4e610ccd87a2ba9413819777d508f71163fcc237
- https://bugzilla.redhat.com/show_bug.cgi?id=1793924
- https://lists.debian.org/debian-lts-announce/2023/09/msg00019.html
More from cesnet
View All →CVE-2021-28906
In function read_yin_leaf() in libyang <= v1.0.225, it doesn't check...
High
7.5
CVE-2021-28905
In function lys_node_free() in libyang <= v1.0.225, it asserts that...
High
7.5
CVE-2021-28904
In function ext_get_plugin() in libyang <= v1.0.225, it doesn't check...
High
7.5
CVE-2021-28903
A stack overflow in libyang <= v1.0.225 can cause a...
High
7.5
CVE-2021-28902
In function read_yin_container() in libyang <= v1.0.225, it doesn't check...
High
7.5
Affected Vendor
cesnet
View all reports →Affected Software
libyang
Vulnerable Versions:
0.11, 0.12, 0.13, 0.14, 0.15, 0.16
Timeline
Official Publish:
January 22nd, 2020
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.