CVE-2019-19334: Cesnet Libyang

Critical severity, CVSS 9.8. EPSS: 3.9% chance of exploitation in the next 30 days.

In all versions of libyang before 1.0-r5, a stack-based buffer overflow was discovered in the way libyang parses YANG files with a leaf of type "identityref". An application that uses libyang to parse untrusted YANG files may be vulnerable to this flaw, which would allow an attacker to cause a denial of service or possibly gain code execution.

Affected products

  • Cesnet Libyang: version 0.11 only; version 0.12 only; version 0.13 only; version 0.14 only; version 0.15 only; version 0.16 only; …
  • Fedoraproject Fedora: version 31 only
  • Red Hat Enterprise Linux: version 8.0 only

Published 2019-12-06. Last modified 2026-06-17.