CVE-2023-26917

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
11/04/2023
Last modified:
11/02/2025

Description

libyang from v2.0.164 to v2.1.30 was discovered to contain a NULL pointer dereference via the function lysp_stmt_validate_value at lys_parse_mem.c.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cesnet:libyang:*:*:*:*:*:*:*:* 2.0.164 (including) 2.1.30 (including)