Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-28906

Опубликовано: 08 мар. 2021
Источник: redhat
CVSS3: 7.5

Описание

In function read_yin_leaf() in libyang <= v1.0.225, it doesn't check whether the value of retval->ext[r] is NULL. In some cases, it can be NULL, which leads to the operation of retval->ext[r]->flags that results in a crash.

A flaw was found in libyang. Missing checks in several read_yin_* functions lead to NULL pointer dereferences possibly allowing a remote attacker to crash an application that uses libyang with user-controlled YIN formats. The highest threat from this vulnerability is the service availability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8libyangWill not fix
Red Hat Enterprise Linux 9libyangNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=1964018libyang: NULL pointer dereference in read_yin_leaf()

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 4 лет назад

In function read_yin_leaf() in libyang <= v1.0.225, it doesn't check whether the value of retval->ext[r] is NULL. In some cases, it can be NULL, which leads to the operation of retval->ext[r]->flags that results in a crash.

CVSS3: 7.5
nvd
больше 4 лет назад

In function read_yin_leaf() in libyang <= v1.0.225, it doesn't check whether the value of retval->ext[r] is NULL. In some cases, it can be NULL, which leads to the operation of retval->ext[r]->flags that results in a crash.

CVSS3: 7.5
debian
больше 4 лет назад

In function read_yin_leaf() in libyang <= v1.0.225, it doesn't check w ...

CVSS3: 7.5
github
больше 3 лет назад

In function read_yin_leaf() in libyang <= v1.0.225, it doesn't check whether the value of retval->ext[r] is NULL. In some cases, it can be NULL, which leads to the operation of retval->ext[r]->flags that results in a crash.

CVSS3: 7.5
fstec
почти 5 лет назад

Уязвимость функции read_yin_leaf() синтаксического анализатора и инструментария языка моделирования данных YANG Libyang, связанная с непроверенным возвращаемым значением, позволяющая нарушителю вызвать отказ в обслуживании

7.5 High

CVSS3