Описание
libyang before 5.2.6 contains a heap use-after-free write vulnerability in lyd_parser_set_data_flags that incorrectly updates metadata list pointers when freeing non-head default metadata entries. Attackers can trigger this vulnerability by submitting crafted YANG XML documents with specific metadata attributes to applications parsing untrusted XML data, causing process crashes or potential code execution.
A flaw was found in libyang. This heap use-after-free write vulnerability, specifically within the lyd_parser_set_data_flags function, occurs when the software incorrectly updates metadata list pointers during the freeing of non-head default metadata entries. A remote attacker can exploit this by submitting specially crafted YANG XML documents containing specific metadata attributes to applications that parse untrusted XML data. Successful exploitation could lead to application process to crash.
Отчет
This vulnerability affects applications using libyang to process XML-encoded YANG data. Red Hat Product Security has assessed this issue as a Moderate severity vulnerability. An authenticated attacker may supply specially crafted YANG/XML input that triggers a heap use-after-free condition during metadata parsing operations, resulting in application crashes and denial of service. Although the vulnerability involves heap memory corruption, the current analysis and reproductions demonstrate denial-of-service impact through application crashes rather than reliable arbitrary code execution. Red Hat therefore assessed the impact as limited to Availability (A:H). Because exploitation generally requires the ability to submit or process crafted YANG configuration data, Red Hat assessed Privileges Required as Low (PR:L).
Меры по смягчению последствий
Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | libyang | Fix deferred | ||
| Red Hat Enterprise Linux 8 | libyang | Fix deferred | ||
| Red Hat Enterprise Linux 9 | libyang | Fix deferred |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
6.5 Medium
CVSS3
Связанные уязвимости
libyang before 5.2.6 contains a heap use-after-free write vulnerability in lyd_parser_set_data_flags that incorrectly updates metadata list pointers when freeing non-head default metadata entries. Attackers can trigger this vulnerability by submitting crafted YANG XML documents with specific metadata attributes to applications parsing untrusted XML data, causing process crashes or potential code execution.
libyang before 5.2.6 contains a heap use-after-free write vulnerability in lyd_parser_set_data_flags that incorrectly updates metadata list pointers when freeing non-head default metadata entries. Attackers can trigger this vulnerability by submitting crafted YANG XML documents with specific metadata attributes to applications parsing untrusted XML data, causing process crashes or potential code execution.
libyang - Heap Use-After-Free Write in XML Metadata Parsing
libyang before 5.2.6 contains a heap use-after-free write vulnerabilit ...
libyang before 5.2.6 contains a heap use-after-free write vulnerability in lyd_parser_set_data_flags that incorrectly updates metadata list pointers when freeing non-head default metadata entries. Attackers can trigger this vulnerability by submitting crafted YANG XML documents with specific metadata attributes to applications parsing untrusted XML data, causing process crashes or potential code execution.
6.5 Medium
CVSS3