CVE-2019-17401: Liblnk Project Liblnk

Low severity, CVSS 3.3. EPSS: 0.4% chance of exploitation in the next 30 days.

libyal liblnk 20191006 has a heap-based buffer over-read in the network_share_name_offset>20 code block of liblnk_location_information_read_data in liblnk_location_information.c, a different issue than CVE-2019-17264. NOTE: the vendor has disputed this as described in the GitHub issue

Affected products

Published 2019-10-09. Last modified 2026-06-17.